STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall NDM Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 05 Jan 2026:

The FortiGate device must use DoD-approved Certificate Authorities (CAs) for public key certificates.

DISA Rule

SV-234198r961863_rule

Vulnerability Number

V-234198

Group Title

SRG-APP-000516-NDM-000344

Rule Version

FGFW-ND-000195

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Obtain CA certificate from a DoD-approved provider.
2. Log in to the FortiGate GUI with Super-Admin privilege.
3. Click System.
4. Click Certificates.
5. Click Import in the toolbar.
6. Click CA Certificate.
7. On the Import CA Certificate page, select Type File.
8. Locate the certificate file and upload the certificate file.
9. Click OK to import the certificate.

Check Contents

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click System.
2. Click Certificates.
3. Verify CAs are approved providers.

If the public key certificates are not from an approved service provider, this is a finding.

Vulnerability Number

V-234198

Documentable

False

Rule Version

FGFW-ND-000195

Severity Override Guidance

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click System.
2. Click Certificates.
3. Verify CAs are approved providers.

If the public key certificates are not from an approved service provider, this is a finding.

Check Content Reference

M

Target Key

5260