STIGQter STIGQter: STIG Summary: Web Server Security Requirements Guide Version: 4 Release: 5 Benchmark Date: 01 Jul 2026:

The web server must only accept client certificates (user and machine) issued by DOD PKI or DOD-approved PKI Certificate Authorities (CAs).

DISA Rule

SV-206430r965407_rule

Vulnerability Number

V-206430

Group Title

SRG-APP-000427

Rule Version

SRG-APP-000427-WSR-000186

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the web server to only allow the use of DOD PKI-established CAs for the session establishment. Configure validation for both the user and machine certificates.

Check Contents

If the web server does not provide PKI-based user authentication intermediary services, this is not applicable.

Verify the web server only allows the use of DOD PKI-established CA for verification when establishing sessions.

Verify both user and machine certificates are being validated when establishing sessions.

If the web server does not validate user and machine certificates using DOD PKI-established CAs, this is a finding.

Vulnerability Number

V-206430

Documentable

False

Rule Version

SRG-APP-000427-WSR-000186

Severity Override Guidance

If the web server does not provide PKI-based user authentication intermediary services, this is not applicable.

Verify the web server only allows the use of DOD PKI-established CA for verification when establishing sessions.

Verify both user and machine certificates are being validated when establishing sessions.

If the web server does not validate user and machine certificates using DOD PKI-established CAs, this is a finding.

Check Content Reference

M

Target Key

2910