The DBMS must only accept end entity certificates issued by DOD PKI or DOD-approved PKI Certification Authorities (CAs) for the establishment of all encrypted sessions.
DISA Rule
SV-206603r1193220_rule
Vulnerability Number
V-206603
Group Title
SRG-APP-000427
Rule Version
SRG-APP-000427-DB-000385
Severity
CAT II
CCI(s)
- CCI-002470 - Only allow the use of organization-defined certificate authorities for verification of the establishment of protected sessions.
Weight
10
Fix Recommendation
Revoke trust in any certificates not issued by a DOD-approved certificate authority. Configure the DBMS to accept only DOD and DOD-approved PKI end-entity certificates.
Check Contents
If the DBMS will accept non-DOD approved PKI end-entity certificates, this is a finding.
Vulnerability Number
V-206603
Documentable
False
Rule Version
SRG-APP-000427-DB-000385
Severity Override Guidance
If the DBMS will accept non-DOD approved PKI end-entity certificates, this is a finding.
Check Content Reference
M
Target Key
2902