STIGQter STIGQter: STIG Summary: BlackBerry Enterprise Mobility Server 3.x Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 26 Jul 2023:

The BlackBerry Enterprise Mobility Server (BEMS) must be configured to use DOD certificates for SSL.

DISA Rule

SV-254717r879887_rule

Vulnerability Number

V-254717

Group Title

SRG-APP-000516-AS-000237

Rule Version

BEMS-03-013600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Replace the auto-generated BEMS SSL certificate with a DOD certificate as follows:

1. Generate a CSR request and obtain a certificate from the DOD CA.
2. Import the certificate into the BEMS keystore.
3. Update the certificate passwords in BEMS.

Check Contents

Verify a DOD SSL certificate has been installed on BEMS as follows:

1. Open the browser.
2. Browse to the BEMS dashboard.
3. Select SSL certificate and view the certificate.
4. Verify the certificate is a DOD certificate (has the DOD CA listed in the certificate).

If the SSL certificate installed on BEMS is not a DOD certificate, this is a finding.

Vulnerability Number

V-254717

Documentable

False

Rule Version

BEMS-03-013600

Severity Override Guidance

Verify a DOD SSL certificate has been installed on BEMS as follows:

1. Open the browser.
2. Browse to the BEMS dashboard.
3. Select SSL certificate and view the certificate.
4. Verify the certificate is a DOD certificate (has the DOD CA listed in the certificate).

If the SSL certificate installed on BEMS is not a DOD certificate, this is a finding.

Check Content Reference

M

Target Key

5488