SV-213545r615939_rule
V-213545
SRG-APP-000427-AS-000264
JBOS-AS-000625
CAT II
10
Locate the cacerts file for the JVM. This can be done using the appropriate find command for the OS and change to the directory where the cacerts file is located.
Remove the certificates that have a CA that is non-DoD approved, and import DoD CA-approved certificates.
Locate the cacerts file for the JVM. This can be done using the appropriate find command for the OS and change to the directory where the cacerts file is located.
To view the certificates stored within this file, execute the java command "keytool -list -v -keystore ./cacerts".
Verify that the Certificate Authority (CA) for each certificate is DoD-approved.
If any certificates have a CA that are not DoD-approved, this is a finding.
V-213545
False
JBOS-AS-000625
Locate the cacerts file for the JVM. This can be done using the appropriate find command for the OS and change to the directory where the cacerts file is located.
To view the certificates stored within this file, execute the java command "keytool -list -v -keystore ./cacerts".
Verify that the Certificate Authority (CA) for each certificate is DoD-approved.
If any certificates have a CA that are not DoD-approved, this is a finding.
M
3987