Item Search

NameAudit NamePluginCategory
ALMA-09-038960 - AlmaLinux OS 9 must map the authenticated identity to the user or group account for PKI-based authentication.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ARBA-VN-000580 - The Remote Access VPN Gateway must use a separate authentication server (e.g., Lightweight Directory Access Protocol [LDAP], Remote Authentication Dial-In User Service [RADIUS], Terminal Access Controller Access-Control System+ [TACACS+] to perform user authentication.DISA HPE Aruba Networking AOS VPN STIG v1r1ArubaOS

IDENTIFICATION AND AUTHENTICATION

ARBA-VN-002430 - AOS, when used as a VPN Gateway, must not accept certificates that have been revoked when using PKI for authentication.DISA HPE Aruba Networking AOS VPN STIG v1r1ArubaOS

IDENTIFICATION AND AUTHENTICATION

BIND-9X-001140 - The BIND 9.x server private key corresponding to the zone-signing key (ZSK) pair must be the only DNSSEC key kept on a name server that supports dynamic updates.DISA BIND 9.x STIG v3r2Unix

IDENTIFICATION AND AUTHENTICATION

BIND-9X-001190 - A unique TSIG key used by a BIND 9.x server must be generated for each pair of communicating hosts.DISA BIND 9.x STIG v3r2Unix

IDENTIFICATION AND AUTHENTICATION

CD12-00-007000 - PostgreSQL, when utilizing PKI-based authentication, must validate certificates by performing RFC 5280-compliant certification path validation.DISA STIG Crunchy Data PostgreSQL OS v3r1Unix

IDENTIFICATION AND AUTHENTICATION

CD12-00-010200 - PostgreSQL must enforce authorized access to all PKI private keys stored/utilized by PostgreSQL.DISA STIG Crunchy Data PostgreSQL OS v3r1Unix

IDENTIFICATION AND AUTHENTICATION

CD16-00-004000 - PostgreSQL, when using PKI-based authentication, must validate certificates by performing RFC 5280-compliant certification path validation.DISA Crunchy Data Postgres 16 STIG v1r3 UnixUnix

IDENTIFICATION AND AUTHENTICATION

CD16-00-004000 - PostgreSQL, when using PKI-based authentication, must validate certificates by performing RFC 5280-compliant certification path validation.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

IDENTIFICATION AND AUTHENTICATION

EDGE-00-000030 - Online revocation checks must be performed.DISA STIG Edge v2r3Windows

IDENTIFICATION AND AUTHENTICATION

EPAS-00-004600 - The EDB Postgres Advanced Server must enforce authorized access to all PKI private keys stored/used by the EDB Postgres Advanced Server.EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1Unix

IDENTIFICATION AND AUTHENTICATION

F5BI-AP-000232 - The F5 BIG-IP appliance must configure OCSP to ensure revoked user credentials are prohibited from establishing an allowed session.DISA F5 BIG-IP Access Policy Manager STIG v2r4F5

IDENTIFICATION AND AUTHENTICATION

F5BI-AP-000233 - The F5 BIG-IP appliance must configure OCSP to ensure revoked machine credentials are prohibited from establishing an allowed session.DISA F5 BIG-IP Access Policy Manager STIG v2r4F5

IDENTIFICATION AND AUTHENTICATION

F5BI-AP-300052 - The F5 BIG-IP appliance must configure certification path validation to ensure revoked machine credentials are prohibited from establishing an allowed session.DISA F5 BIG-IP TMOS ALG STIG v1r2F5

IDENTIFICATION AND AUTHENTICATION

F5BI-AP-300054 - The F5 BIG-IP appliance providing user authentication intermediary services using PKI-based user authentication must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.DISA F5 BIG-IP TMOS ALG STIG v1r2F5

IDENTIFICATION AND AUTHENTICATION

F5BI-AP-300154 - The F5 BIG-IP appliance must configure certificate path validation to ensure revoked user credentials are prohibited from establishing an allowed session.DISA F5 BIG-IP TMOS ALG STIG v1r2F5

IDENTIFICATION AND AUTHENTICATION

F5BI-LT-000317 - The F5 BIG-IP appliance must configure OCSP to ensure revoked credentials are prohibited from establishing an allowed session.DISA F5 BIG-IP Local Traffic Manager STIG v2r4F5

IDENTIFICATION AND AUTHENTICATION

FFOX-00-000003 - Firefox must be configured to ask which certificate to present to a website when a certificate is required.DISA STIG Mozilla Firefox Windows v6r7Windows

IDENTIFICATION AND AUTHENTICATION

FFOX-00-000016 - Firefox must have the DOD root certificates installed.DISA STIG Mozilla Firefox Linux v6r7Unix

IDENTIFICATION AND AUTHENTICATION

FFOX-00-000016 - Firefox must have the DOD root certificates installed.DISA STIG Mozilla Firefox MacOS v6r7Unix

IDENTIFICATION AND AUTHENTICATION

FFOX-00-000016 - Firefox must have the DOD root certificates installed.DISA STIG Mozilla Firefox Windows v6r7Windows

IDENTIFICATION AND AUTHENTICATION

JRE8-UX-000100 - Oracle JRE 8 must set the option to enable online certificate validation - deployment.security.validation.ocspDISA STIG Oracle JRE 8 Unix v1r3Unix

IDENTIFICATION AND AUTHENTICATION

JRE8-UX-000160 - Oracle JRE 8 must lock the option to enable users to check for revocation - deployment.security.revocation.checkDISA STIG Oracle JRE 8 Unix v1r3Unix

IDENTIFICATION AND AUTHENTICATION

MD7X-00-004100 - MongoDB must enforce authorized access to all PKI private keys stored/used by MongoDB.DISA MongoDB Enterprise Advanced 7.x STIG v1r2 UnixUnix

IDENTIFICATION AND AUTHENTICATION

MD7X-00-004200 - MongoDB must map the PKI-authenticated identity to an associated user account.DISA MongoDB Enterprise Advanced 7.x STIG v1r2 MongoDBMongoDB

IDENTIFICATION AND AUTHENTICATION

Monterey - Issue or Obtain Public Key Certificates from an Approved Service ProviderNIST macOS Monterey v1.0.0 - 800-53r5 HighUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

Monterey - Issue or Obtain Public Key Certificates from an Approved Service ProviderNIST macOS Monterey v1.0.0 - 800-53r5 ModerateUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

Monterey - Issue or Obtain Public Key Certificates from an Approved Service ProviderNIST macOS Monterey v1.0.0 - 800-53r4 ModerateUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

Monterey - Issue or Obtain Public Key Certificates from an Approved Service ProviderNIST macOS Monterey v1.0.0 - CNSSI 1253Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

MYS8-00-004800 - The MySQL Database Server 8.0 must enforce authorized access to all PKI private keys stored/utilized by the MySQL Database Server 8.0.DISA Oracle MySQL 8.0 v2r2 DBMySQLDB

IDENTIFICATION AND AUTHENTICATION

O19C-00-015200 - Oracle Database, when using public key infrastructure (PKI)-based authentication, must enforce authorized access to the corresponding private key.DISA Oracle Database 19c STIG v1r5 UnixUnix

IDENTIFICATION AND AUTHENTICATION

O19C-00-015200 - Oracle Database, when using public key infrastructure (PKI)-based authentication, must enforce authorized access to the corresponding private key.DISA Oracle Database 19c STIG v1r3 UnixUnix

IDENTIFICATION AND AUTHENTICATION

O19C-00-015300 - Oracle Database must map the authenticated identity to the user account using public key infrastructure (PKI)-based authentication.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

OL08-00-010100 - OL 8, for certificate-based authentication, must enforce authorized access to the corresponding private key.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OS10-NDM-000480 - The Dell OS10 Switch must be configured to use DOD-approved OCSP responders or CRLs to validate certificates used for PKI-based authentication.DISA Dell OS10 Switch NDM STIG v1r1Dell_OS10

IDENTIFICATION AND AUTHENTICATION

RHEL-08-010100 - RHEL 8, for certificate-based authentication, must enforce authorized access to the corresponding private key.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611190 - RHEL 9, for PKI-based authentication, must enforce authorized access to the corresponding private key.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

SLEM-05-255085 - SLEM 5, for PKI-based authentication, must enforce authorized access to the corresponding private key.DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-254030 - Ubuntu 22.04 LTS must map the authenticated identity to the user or group account for PKI-based authentication.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-24-400370 - Ubuntu 24.04 LTS must map the authenticated identity to the user or group account for PKI-based authentication.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-24-400380 - Ubuntu 24.04 LTS for PKI-based authentication, must implement a local cache of revocation data in case of the inability to access revocation information via the network.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

VCLD-67-000025 - VAMI must protect the keystore from unauthorized access.DISA STIG VMware vSphere 6.7 VAMI-lighttpd v1r3Unix

IDENTIFICATION AND AUTHENTICATION

VCLD-70-000017 - VAMI must protect the keystore from unauthorized access - MIME that invoke OS shell programs disabled.DISA STIG VMware vSphere 7.0 VAMI v1r2Unix

IDENTIFICATION AND AUTHENTICATION

VCLD-80-000040 The vCenter VAMI service must restrict access to the web server's private key.DISA VMware vSphere 8.0 vCenter Appliance Management Interface (VAMI) STIG v2r1Unix

IDENTIFICATION AND AUTHENTICATION

VCPG-70-000012 - VMware Postgres must enforce authorized access to all public key infrastructure (PKI) private keys.DISA STIG VMware vSphere 7.0 PostgreSQL v1r2Unix

IDENTIFICATION AND AUTHENTICATION

VCRP-67-000007 - The rhttpproxy private key file must be protected from unauthorized access.DISA STIG VMware vSphere 6.7 RhttpProxy v1r3Unix

IDENTIFICATION AND AUTHENTICATION

VCRP-70-000005 - The Envoy private key file must be protected from unauthorized access.DISA STIG VMware vSphere 7.0 RhttpProxy v1r1Unix

IDENTIFICATION AND AUTHENTICATION

WN22-DC-000280 - Windows Server 2022 domain controllers must have a PKI server certificate.DISA Microsoft Windows Server 2022 STIG v2r8Windows

IDENTIFICATION AND AUTHENTICATION

WN22-DC-000290 - Windows Server 2022 domain controller PKI certificates must be issued by the DOD PKI or an approved External Certificate Authority (ECA).DISA Microsoft Windows Server 2022 STIG v2r8Windows

IDENTIFICATION AND AUTHENTICATION

WN25-DC-000290 - Windows Server 2025 domain Controller PKI certificates must be issued by the DOD PKI or an approved External Certificate Authority (ECA).DISA Microsoft Windows Server 2025 STIG v1r1Windows

IDENTIFICATION AND AUTHENTICATION