SV-205003r831380_rule
V-205003
SRG-NET-000355
SRG-NET-000355-ALG-000117
CAT II
10
If PKI-based user authentication intermediary services are provided, configure the ALG to only accept end entity certificates issued by DoD PKI or DoD-approved PKI CAs for the establishment of protected sessions.
If the ALG does not provide PKI-based user authentication intermediary services, this is not applicable.
Verify the ALG only accepts end entity certificates issued by DoD PKI or DoD-approved PKI CAs for the establishment of protected sessions.
If the ALG accepts non-DoD approved PKI end entity certificates, this is a finding.
V-205003
False
SRG-NET-000355-ALG-000117
If the ALG does not provide PKI-based user authentication intermediary services, this is not applicable.
Verify the ALG only accepts end entity certificates issued by DoD PKI or DoD-approved PKI CAs for the establishment of protected sessions.
If the ALG accepts non-DoD approved PKI end entity certificates, this is a finding.
M
2904