SV-218749r558649_rule
V-218749
SRG-APP-000172-WSR-000104
IIST-SI-000220
CAT II
10
Note: If the server being reviewed is a public IIS 10.0 web server, this is Not Applicable.
Note: If certificate handling is performed at the Proxy/Load Balancer, this is not a finding.
Follow the procedures below for each site hosted on the IIS 10.0 web server:
Open the IIS 10.0 Manager.
Double-click the "SSL Settings" icon.
Verify the "Clients Certificate Required" check box is selected.
Select "Apply" from the "Actions" pane.
Note: If the server being reviewed is a public IIS 10.0 web server, this is Not Applicable.
Note: If certificate handling is performed at the Proxy/Load Balancer, this is not a finding.
Follow the procedures below for each site hosted on the IIS 10.0 web server:
Open the IIS 10.0 Manager.
Double-click the "SSL Settings" icon.
Verify the "Clients Certificate Required" check box is selected.
If the "Clients Certificate Required" check box is not selected, this is a finding.
V-218749
False
IIST-SI-000220
Note: If the server being reviewed is a public IIS 10.0 web server, this is Not Applicable.
Note: If certificate handling is performed at the Proxy/Load Balancer, this is not a finding.
Follow the procedures below for each site hosted on the IIS 10.0 web server:
Open the IIS 10.0 Manager.
Double-click the "SSL Settings" icon.
Verify the "Clients Certificate Required" check box is selected.
If the "Clients Certificate Required" check box is not selected, this is a finding.
M
4051