STIGQter STIGQter: STIG Summary: Trend Micro TippingPoint NDM Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Apr 2025:

The TippingPoint SMS must obtain its public key certificates from an appropriate certificate policy through an approved service provider.

DISA Rule

SV-242257r961863_rule

Vulnerability Number

V-242257

Group Title

SRG-APP-000516-NDM-000344

Rule Version

TIPP-NM-000600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the SMS client, ensure the certificate is signed by an authorized DoD Certificate Authority.

1. Select Admin >> Certificate Management >> Certificates.
2. Select import.
3. The SMS can import a certificate with a private key file separately, or can import a PKCS12/PFX file. The user can use OpenSSL on a separate system to generate the certificate signing request (CSR) or can use the CSR generation tool on the SMS under Admin, Certificate Management, Signing Requests. The CSR must ensure the following attributes are added to the CSR if using the SMS tool: 2048 RSA key size and a DNS Subject Alternative Name (SAN) - if required.

Check Contents

In the SMS client, ensure the certificate is signed by an authorized DoD Certificate Authority.

Select Admin >> Certificate Management >> Certificates.

If there is no certificate, or the certificate is signed by a CA that is not authorized in the DoD, this is a finding.

Vulnerability Number

V-242257

Documentable

False

Rule Version

TIPP-NM-000600

Severity Override Guidance

In the SMS client, ensure the certificate is signed by an authorized DoD Certificate Authority.

Select Admin >> Certificate Management >> Certificates.

If there is no certificate, or the certificate is signed by a CA that is not authorized in the DoD, this is a finding.

Check Content Reference

M

Target Key

5369