STIGQter STIGQter: STIG Summary: VMW vRealize Automation 7.x vAMI Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

If the vAMI uses PKI Class 3 or Class 4 certificates, the certificates must be DoD- or CNSS-approved. If the vAMI does not use PKI Class 3 or Class 4 certificates, this requirement is Not Applicable.

DISA Rule

SV-100923r1_rule

Vulnerability Number

V-90273

Group Title

SRG-APP-000514-AS-000137

Rule Version

VRAU-VA-000640

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If the vAMI is using PKI Class 3 or Class 4 certificates, install certificates that are DoD or CNSS approved.

Check Contents

Interview the ISSO and/or the SA.

Determine if the vAMI is using PKI Class 3 or Class 4 certificates.

If the vAMI is using PKI Class 3 or Class 4 certificates, and the certificates are not DoD- or CNSS-approved, this is a finding.

Vulnerability Number

V-90273

Documentable

False

Rule Version

VRAU-VA-000640

Severity Override Guidance

Interview the ISSO and/or the SA.

Determine if the vAMI is using PKI Class 3 or Class 4 certificates.

If the vAMI is using PKI Class 3 or Class 4 certificates, and the certificates are not DoD- or CNSS-approved, this is a finding.

Check Content Reference

M

Target Key

3449

Comments