STIGQter STIGQter: STIG Summary: ISEC7 Sphere Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The ISEC7 SPHERE must allow the use of DOD PKI established certificate authorities for verification of the establishment of protected sessions.

DISA Rule

SV-224771r1013827_rule

Vulnerability Number

V-224771

Group Title

SRG-APP-000427

Rule Version

ISEC-06-001960

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the ISEC7 SPHERE Server.
Navigate to %Install Drive%/Program Files/ISEC7 SPHERE/tomcat/bin.
Run tomcat9w.bat and select the JAVA tab in the window that opens.
Under "Java options" add "-Djavax.net.ssl.trustStoreType=Windows-ROOT" and select "OK".
Restart the ISEC7 SPHERE Web service.

Check Contents

Log in to the ISEC7 SPHERE Server.
Navigate to %Install Drive%/Program Files/ISEC7 SPHERE/tomcat/bin.
Run tomcat9w.bat and select the JAVA tab in the window that opens.
Under "Java options" verify "-Djavax.net.ssl.trustStoreType=Windows-ROOT" is listed.

If "-Djavax.net.ssl.trustStoreType=Windows-ROOT" is not listed, this is a finding.

Vulnerability Number

V-224771

Documentable

False

Rule Version

ISEC-06-001960

Severity Override Guidance

Log in to the ISEC7 SPHERE Server.
Navigate to %Install Drive%/Program Files/ISEC7 SPHERE/tomcat/bin.
Run tomcat9w.bat and select the JAVA tab in the window that opens.
Under "Java options" verify "-Djavax.net.ssl.trustStoreType=Windows-ROOT" is listed.

If "-Djavax.net.ssl.trustStoreType=Windows-ROOT" is not listed, this is a finding.

Check Content Reference

M

Target Key

4200