STIGQter STIGQter: STIG Summary: Web Server Security Requirements Guide Version: 4 Release: 5 Benchmark Date: 01 Jul 2026:

Only authenticated system administrators or the designated PKI Sponsor for the web server must have access to the web servers private key.

DISA Rule

SV-206389r961041_rule

Vulnerability Number

V-206389

Group Title

SRG-APP-000176

Rule Version

SRG-APP-000176-WSR-000096

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the web server to ensure only authenticated and authorized users can access the web server's private key.

Check Contents

If the web server does not have a private key, this is N/A.

Review the web server documentation and deployed configuration to determine whether only authenticated system administrators and the designated PKI Sponsor for the web server can access the web server private key.

If the private key is accessible by unauthenticated or unauthorized users, this is a finding.

Vulnerability Number

V-206389

Documentable

False

Rule Version

SRG-APP-000176-WSR-000096

Severity Override Guidance

If the web server does not have a private key, this is N/A.

Review the web server documentation and deployed configuration to determine whether only authenticated system administrators and the designated PKI Sponsor for the web server can access the web server private key.

If the private key is accessible by unauthenticated or unauthorized users, this is a finding.

Check Content Reference

M

Target Key

2910