SV-220386r961596_rule
V-220386
SRG-APP-000427-DB-000385
ML09-00-008400
CAT II
10
Configure MarkLogic to accept only DoD and DoD-approved PKI end-entity certificates by revoking trust in any certificates not issued by a DoD-approved certificate authority.
Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Security icon.
2. Click the Certificate Authorities icon.
3. Remove all PKI end-entity certificates not approved by DoD.
Review MarkLogic settings to determine whether the server will accept non-DoD approved PKI end-entity certificates, this is a finding.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Security icon.
2. Click the Certificate Authorities icon.
3. If there are any PKI end-entity certificates that are not DoD approved, this is a finding.
V-220386
False
ML09-00-008400
Review MarkLogic settings to determine whether the server will accept non-DoD approved PKI end-entity certificates, this is a finding.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Security icon.
2. Click the Certificate Authorities icon.
3. If there are any PKI end-entity certificates that are not DoD approved, this is a finding.
M
4064