800-53|IA-5(2)(b)

Title

PKI-BASED AUTHENTICATION

Description

Enforces authorized access to the corresponding private key;

Reference Item Details

Category: IDENTIFICATION AND AUTHENTICATION

Family: IDENTIFICATION AND AUTHENTICATION

Audit Items

View all Reference Audit Items

NamePluginAudit Name
2.3.14.1 Ensure 'System cryptography: Force strong key protection for user keys stored on the computer' is set to 'User is prompted when the key is first used' or higherWindowsCIS Windows 7 Workstation Level 2 v3.2.0
2.3.14.1 Ensure 'System cryptography: Force strong key protection for user keys stored on the computer' is set to 'User is prompted when the key is first used' or higherWindowsCIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0
AIX7-00-003004 - AIX SSH private host key files must have mode 0600 or less permissive.UnixDISA STIG AIX 7.x v2r5
AOSX-13-067035 - The macOS system must enable certificate for smartcards.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-14-003002 - The macOS system must enable certificate for smartcards.UnixDISA STIG Apple Mac OSX 10.14 v2r6
APPNET0052 - Encryption keys used for the .NET Strong Name Membership Condition must be protected.WindowsDISA STIG for Microsoft Dot Net Framework 4.0 v2r1
AS24-U1-000360 - The Apache web server must be configured to use a specified IP address and port - IP or Port OnlyUnixDISA STIG Apache Server 2.4 Unix Server v2r5
AS24-U1-000360 - The Apache web server must be configured to use a specified IP address and port - IP or Port OnlyUnixDISA STIG Apache Server 2.4 Unix Server v2r5 Middleware
AS24-U1-000360 - The Apache web server must be configured to use a specified IP address and port - Zero IPs OnlyUnixDISA STIG Apache Server 2.4 Unix Server v2r5 Middleware
AS24-U1-000360 - The Apache web server must be configured to use a specified IP address and port - Zero IPs OnlyUnixDISA STIG Apache Server 2.4 Unix Server v2r5
AS24-U2-000390 - Only authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key.UnixDISA STIG Apache Server 2.4 Unix Site v2r2
AS24-U2-000390 - Only authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key.UnixDISA STIG Apache Server 2.4 Unix Site v2r2 Middleware
AS24-W2-000390 - Only authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key.WindowsDISA STIG Apache Server 2.4 Windows Site v2r1
Big Sur - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
BIND-9X-001110 - The TSIG keys used with the BIND 9.x implementation must be owned by a privileged account.UnixDISA BIND 9.x STIG v2r2
BIND-9X-001111 - The TSIG keys used with the BIND 9.x implementation must be group owned by a privileged account.UnixDISA BIND 9.x STIG v2r2
BIND-9X-001112 - The read and write access to a TSIG key file used by a BIND 9.x server must be restricted to only the account that runs the name server software.UnixDISA BIND 9.x STIG v2r2
BIND-9X-001133 - The BIND 9.x server private key corresponding to the ZSK pair must be the only DNSSEC key kept on a name server that supports dynamic updates.UnixDISA BIND 9.x STIG v2r2
BIND-9X-001150 - The BIND 9.x server signature generation using the KSK must be done off-line, using the KSK-private key stored off-line.UnixDISA BIND 9.x STIG v2r2
Catalina - Set Smartcard Certificate Trust to HighUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Set Smartcard Certificate Trust to HighUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Set Smartcard Certificate Trust to HighUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Catalina v1.5.0 - All Profiles
DKER-EE-002380 - The certificate chain used by Universal Control Plane (UCP) client bundles must match what is defined in the System Security Plan (SSP) in Docker Enterprise.UnixDISA STIG Docker Enterprise 2.x Linux/Unix v2r1
DKER-EE-002400 - Docker Enterprise Swarm manager must be run in auto-lock mode.UnixDISA STIG Docker Enterprise 2.x Linux/Unix v2r1
DKER-EE-002410 - Docker Enterprise secret management commands must be used for managing secrets in a Swarm cluster.UnixDISA STIG Docker Enterprise 2.x Linux/Unix v2r1
EP11-00-004600 - The EDB Postgres Advanced Server must enforce authorized access to all PKI private keys stored/utilized by the EDB Postgres Advanced Server.WindowsEDB PostgreSQL Advanced Server v11 Windows OS Audit v2r1
GEN005523 - The SSH private host key files must have mode 0600 or less permissive.UnixDISA STIG for Oracle Linux 5 v2r1
JBOS-AS-000320 - The JBoss server must be configured to restrict access to the web servers private key to authenticated system administrators - directoryUnixDISA RedHat JBoss EAP 6.3 STIG v2r3
JBOS-AS-000320 - The JBoss server must be configured to restrict access to the web servers private key to authenticated system administrators - keystore fileUnixDISA RedHat JBoss EAP 6.3 STIG v2r3
MD3X-00-000360 - MongoDB must enforce authorized access to all PKI private keys stored/utilized by MongoDB - CAFileUnixDISA STIG MongoDB Enterprise Advanced 3.x v2r1 OS
MD3X-00-000360 - MongoDB must enforce authorized access to all PKI private keys stored/utilized by MongoDB - PEMKeyFileUnixDISA STIG MongoDB Enterprise Advanced 3.x v2r1 OS
MD4X-00-003100 - MongoDB must enforce authorized access to all PKI private keys stored/utilized by MongoDB. - CAFileUnixDISA STIG MongoDB Enterprise Advanced 4.x v1r1 OS
MD4X-00-003100 - MongoDB must enforce authorized access to all PKI private keys stored/utilized by MongoDB. - PEMKeyFileUnixDISA STIG MongoDB Enterprise Advanced 4.x v1r1 OS
Monterey - Set Smartcard Certificate Trust to HighUnixNIST macOS Monterey v1.0.0 - 800-53r4 High
Monterey - Set Smartcard Certificate Trust to HighUnixNIST macOS Monterey v1.0.0 - All Profiles
Monterey - Set Smartcard Certificate Trust to HighUnixNIST macOS Monterey v1.0.0 - 800-53r5 High
Monterey - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Monterey v1.0.0 - All Profiles
Monterey - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Monterey v1.0.0 - 800-53r5 Moderate
Monterey - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Monterey v1.0.0 - CNSSI 1253
Monterey - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Monterey v1.0.0 - 800-53r4 Moderate
MYS8-00-004800 - The MySQL Database Server 8.0 must enforce authorized access to all PKI private keys stored/utilized by the MySQL Database Server 8.0 - private pem filesUnixDISA Oracle MySQL 8.0 v1r2 OS Linux
MYS8-00-004800 - The MySQL Database Server 8.0 must enforce authorized access to all PKI private keys stored/utilized by the MySQL Database Server 8.0 - public pem filesUnixDISA Oracle MySQL 8.0 v1r2 OS Linux
O112-C1-015400 - The DBMS, when using PKI-based authentication, must enforce authorized access to the corresponding private key - SSL_CIPHER_SUITESWindowsDISA STIG Oracle 11.2g v2r3 Windows