The DBMS must only accept end entity certificates issued by DoD PKI or DoD-approved PKI Certification Authorities (CAs) for the establishment of all encrypted sessions.
DISA Rule
SV-206603r617447_rule
Vulnerability Number
V-206603
Group Title
SRG-APP-000427
Rule Version
SRG-APP-000427-DB-000385
Severity
CAT II
CCI(s)
- CCI-002470 - The information system only allows the use of organization-defined certificate authorities for verification of the establishment of protected sessions.
Weight
10
Fix Recommendation
Revoke trust in any certificates not issued by a DoD-approved certificate authority. Configure the DBMS to accept only DoD and DoD-approved PKI end-entity certificates.
Check Contents
If the DBMS will accept non-DoD approved PKI end-entity certificates, this is a finding.
Vulnerability Number
V-206603
Documentable
False
Rule Version
SRG-APP-000427-DB-000385
Severity Override Guidance
If the DBMS will accept non-DoD approved PKI end-entity certificates, this is a finding.
Check Content Reference
M
Target Key
2902
Comments