STIGQter STIGQter: STIG Summary: EDB Postgres Advanced Server v11 on Windows Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Oct 2020:

The EDB Postgres Advanced Server must only accept end entity certificates issued by DoD PKI or DoD-approved PKI Certification Authorities (CAs) for the establishment of all encrypted sessions.

DISA Rule

SV-224205r508023_rule

Vulnerability Number

V-224205

Group Title

SRG-APP-000427-DB-000385

Rule Version

EP11-00-009100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Contact your program security office to request DoD issued certificates:

root.crt (CA Certificate)
server.crt
server.key

Check Contents

In a Windows CMD prompt, run this command:

CertUtil <postgresql data directory>\server.crt

If the "Issuer" that is printed out is not a DoD entity, this is a finding.

Vulnerability Number

V-224205

Documentable

False

Rule Version

EP11-00-009100

Severity Override Guidance

In a Windows CMD prompt, run this command:

CertUtil <postgresql data directory>\server.crt

If the "Issuer" that is printed out is not a DoD entity, this is a finding.

Check Content Reference

M

Target Key

4107

Comments