STIGQter STIGQter: STIG Summary: Mozilla Firefox Security Technical Implementation Guide Version: 5 Release: 1 Benchmark Date: 22 Jan 2021:

The DOD Root Certificate is not installed.

DISA Rule

SV-223179r612236_rule

Vulnerability Number

V-223179

Group Title

SRG-APP-000175

Rule Version

DTBG010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Install the DOD root certificates.

Check Contents

Navigate to Tools >> Options >> Advanced >> Certificates tab >> View Certificates button. On the Certificate Manager window, select the "Authorities" tab. Scroll through the Certificate Name list to the U.S. Government heading. Look for the entries for DoD Root CA 2, DoD Root CA 3, and DoD Root CA 4.

If there are entries for DoD Root CA 2, DoD Root CA 3, and DoD Root CA 4, select them individually.

Click the "View" button.

Verify the publishing organization is "US Government."

If there are no entries for the DoD Root CA 2, DoD Root CA 3, and DoD Root CA 4, this is a finding.

Note: In a Windows environment, use of policy setting "security.enterprise_roots.enabled=true" will point Firefox to the Windows Trusted Root Certification Authority Store, this is not a finding.

Vulnerability Number

V-223179

Documentable

False

Rule Version

DTBG010

Severity Override Guidance

Navigate to Tools >> Options >> Advanced >> Certificates tab >> View Certificates button. On the Certificate Manager window, select the "Authorities" tab. Scroll through the Certificate Name list to the U.S. Government heading. Look for the entries for DoD Root CA 2, DoD Root CA 3, and DoD Root CA 4.

If there are entries for DoD Root CA 2, DoD Root CA 3, and DoD Root CA 4, select them individually.

Click the "View" button.

Verify the publishing organization is "US Government."

If there are no entries for the DoD Root CA 2, DoD Root CA 3, and DoD Root CA 4, this is a finding.

Note: In a Windows environment, use of policy setting "security.enterprise_roots.enabled=true" will point Firefox to the Windows Trusted Root Certification Authority Store, this is not a finding.

Check Content Reference

M

Target Key

4097

Comments