STIGQter STIGQter: STIG Summary: Authentication, Authorization, and Accounting Services (AAA) Security Requirements Guide Version: 1 Release: 2 Benchmark Date: 24 Jan 2020:

AAA Services must be configured to only accept certificates issued by a DoD-approved Certificate Authority for PKI-based authentication.

DISA Rule

SV-95635r1_rule

Vulnerability Number

V-80925

Group Title

SRG-APP-000175-AAA-000570

Rule Version

SRG-APP-000175-AAA-000570

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure AAA Services to only accept certificates issued by a DoD-approved Certificate Authority for PKI-based authentication.

Check Contents

Verify AAA Services are configured to only accept certificates issued by a DoD-approved Certificate Authority for PKI-based authentication.

If AAA Services are not configured to only accept certificates issued by a DoD-approved Certificate Authority, this is a finding.

Vulnerability Number

V-80925

Documentable

False

Rule Version

SRG-APP-000175-AAA-000570

Severity Override Guidance

Verify AAA Services are configured to only accept certificates issued by a DoD-approved Certificate Authority for PKI-based authentication.

If AAA Services are not configured to only accept certificates issued by a DoD-approved Certificate Authority, this is a finding.

Check Content Reference

M

Target Key

3357

Comments