STIGQter STIGQter: STIG Summary: HYCU Protege Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The HYCU virtual appliance must obtain its public key certificates from an appropriate certificate policy through an approved service provider.

DISA Rule

SV-268258r1039645_rule

Vulnerability Number

V-268258

Group Title

SRG-APP-000516-NDM-000344

Rule Version

HYCU-ND-000500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the HYCU Web UI and generate a CSR within the gear menu and "SSL Certificates" menu.

Submit this CSR to a DOD PKI authority to have a new certificate created.

Note: By default, HYCU is configured with a self-signed certificate, but this can be replaced with a DOD-issued certificate. This certificate can be configured by logging in to the HYCU Web UI, navigating to the gear menu and "SSL Certificates" menu, and importing the DOD-issued certificate.

Check Contents

Open a new HYCU Web UI browser tab and verify there is no warning prompt before proceeding to the Web UI login page.

If a warning appears in the web browser stating, "Not secure", this is a finding.

Vulnerability Number

V-268258

Documentable

False

Rule Version

HYCU-ND-000500

Severity Override Guidance

Open a new HYCU Web UI browser tab and verify there is no warning prompt before proceeding to the Web UI login page.

If a warning appears in the web browser stating, "Not secure", this is a finding.

Check Content Reference

M

Target Key

5660