SV-79949r1_rule
V-65459
SRG-APP-000175
AGIS-00-000077
CAT II
10
Configure the ArcGIS Server to ensure PKI-based authenticated endpoints validate certificates by constructing a certification path. Substitute the target environment’s values for [bracketed] variables.
On each GIS Server in the ArcGIS Server Site, left-shift + right-click on Internet Explorer >> Run as a different user >> log on using the "[ArcGIS Server]" account.
Within Internet Explorer, click Tools >> Internet Options.
Open the "Advanced" tab. Within the "Security" section, check "Check for publisher's certificate revocation".
Within the "Security" section, check "Check for server certificate revocation".
Restart the server.
Access to the "[ArcGIS Server]" account is required to make this change.
Review the ArcGIS Server configuration to ensure PKI-based authenticated endpoints validate certificates by constructing a certification path. Substitute the target environment’s values for [bracketed] variables.
1. On each GIS Server in the ArcGIS Server Site, left-shift + right-click on Internet Explorer >> Run as a different user >> log on using the "[ArcGIS Server]" account.
Within Internet Explorer, click Tools >> Internet Options.
Open the "Advanced" tab. Within the "Security" section, verify "Check for publisher's certificate revocation" is checked.
If "Check for publisher's certificate revocation" is not checked, this is a finding.
2. Within the "Security" section, verify "Check for server certificate revocation" is checked.
If "Check for server certificate revocation" is not checked, this is a finding.
Access to the "[ArcGIS Server]" account is required to perform this check.
V-65459
False
AGIS-00-000077
Review the ArcGIS Server configuration to ensure PKI-based authenticated endpoints validate certificates by constructing a certification path. Substitute the target environment’s values for [bracketed] variables.
1. On each GIS Server in the ArcGIS Server Site, left-shift + right-click on Internet Explorer >> Run as a different user >> log on using the "[ArcGIS Server]" account.
Within Internet Explorer, click Tools >> Internet Options.
Open the "Advanced" tab. Within the "Security" section, verify "Check for publisher's certificate revocation" is checked.
If "Check for publisher's certificate revocation" is not checked, this is a finding.
2. Within the "Security" section, verify "Check for server certificate revocation" is checked.
If "Check for server certificate revocation" is not checked, this is a finding.
Access to the "[ArcGIS Server]" account is required to perform this check.
M
2961