SV-215789r557356_rule
V-215789
SRG-NET-000355-ALG-000117
F5BI-LT-000213
CAT II
10
Configure the BIG-IP Core to only allow the use of DoD-approved PKI-established certificate authorities for verification of the establishment of protected sessions.
Verify the BIG-IP Core is configured to allow the use of DoD-approved PKI-established certificate authorities for verification of the establishment of protected sessions.
Navigate to the BIG-IP System manager >> System >> File Management >> SSL Certificate List.
Validate that an approved DOD CA Bundle is listed.
If the BIG-IP Core is not configured to use DoD-approved PKI-established certificate authorities for verification of the establishment of protected sessions, this is a finding.
V-215789
False
F5BI-LT-000213
Verify the BIG-IP Core is configured to allow the use of DoD-approved PKI-established certificate authorities for verification of the establishment of protected sessions.
Navigate to the BIG-IP System manager >> System >> File Management >> SSL Certificate List.
Validate that an approved DOD CA Bundle is listed.
If the BIG-IP Core is not configured to use DoD-approved PKI-established certificate authorities for verification of the establishment of protected sessions, this is a finding.
M
4019