SV-214460r508659_rule
V-214460
SRG-APP-000172-WSR-000104
IISW-SI-000220
CAT II
10
Note: If the server being reviewed is a public IIS 8.5 web server, this is Not Applicable.
Note: If certificate handling is performed at the Proxy/Load Balancer, this is not a finding.
Follow the procedures below for each site hosted on the IIS 8.5 web server:
Open the IIS 8.5 Manager.
Double-click the "SSL Settings" icon.
Verify the "Clients Certificate Required" check box is selected.
Select "Apply" from the "Actions" pane.
Note: If the server being reviewed is a public IIS 8.5 web server, this is Not Applicable.
Note: If certificate handling is performed at the Proxy/Load Balancer, this is not a finding.
Follow the procedures below for each site hosted on the IIS 8.5 web server:
Open the IIS 8.5 Manager.
Double-click the "SSL Settings" icon.
Verify the "Clients Certificate Required" check box is selected.
If the "Clients Certificate Required" check box is not selected, this is a finding.
V-214460
False
IISW-SI-000220
Note: If the server being reviewed is a public IIS 8.5 web server, this is Not Applicable.
Note: If certificate handling is performed at the Proxy/Load Balancer, this is not a finding.
Follow the procedures below for each site hosted on the IIS 8.5 web server:
Open the IIS 8.5 Manager.
Double-click the "SSL Settings" icon.
Verify the "Clients Certificate Required" check box is selected.
If the "Clients Certificate Required" check box is not selected, this is a finding.
M
4001