SV-266984r1040891_rule
V-266984
SRG-NET-000164-VPN-000560
ARBA-VN-000560
CAT II
10
Configure AOS using the web interface:
1. Navigate to Configuration >> System >> Certificates tab.
2. Under "Import Certificates", click the plus sign (+) and upload the trusted root CA. Provide the certificate name, upload the certificate file, and select the matching certificate format.
3. Choose the TrustedCA Certificate type.
4. Click Submit >> Pending Changes >> and Deploy Changes.
1. Verify the AOS configuration with the following command:
show crypto-local pki trusted CA
2. Note the name(s) of each trust CA.
show crypto-local pki trustedCA <name>
3. Verify that each trusted CA is a valid DOD PKI CA.
If the trusted CAs are not DOD PKI or no DOD PKI CAs are present, this is a finding.
V-266984
False
ARBA-VN-000560
1. Verify the AOS configuration with the following command:
show crypto-local pki trusted CA
2. Note the name(s) of each trust CA.
show crypto-local pki trustedCA <name>
3. Verify that each trusted CA is a valid DOD PKI CA.
If the trusted CAs are not DOD PKI or no DOD PKI CAs are present, this is a finding.
M
5645