SV-70281r2_rule
V-56027
SRG-APP-000427-WSR-000186
SRG-APP-000427-WSR-000186
CAT II
10
Configure the web server to only accept DoD and DoD-approved PKI client certificates.
Review the web server deployed configuration to determine if the web server will accept client certificates issued by unapproved PKIs. The authoritative list of DoD-approved PKIs is published at http://iase.disa.mil/pki-pke/interoperability.
If the web server will accept non-DoD approved PKI client certificates, this is a finding.
V-56027
False
SRG-APP-000427-WSR-000186
Review the web server deployed configuration to determine if the web server will accept client certificates issued by unapproved PKIs. The authoritative list of DoD-approved PKIs is published at http://iase.disa.mil/pki-pke/interoperability.
If the web server will accept non-DoD approved PKI client certificates, this is a finding.
M
2557