STIGQter STIGQter: STIG Summary: Active Directory Forest Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 02 Jul 2025:

Windows Server hosting Active Directory Certificate Services (AD CS) must enforce Certificate Authority (CA) certificate management approval for certificate requests.

DISA Rule

SV-269098r1106505_rule

Vulnerability Number

V-269098

Group Title

SRG-OS-000324

Rule Version

AD.3145_AD

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

In the AD CS web server properties, select "VulnerableCertTemplate" properties and then select "Subject Name" and "Supply in the request".

Certificate templates with the following extended key usages must require manual approval in all cases:
i. Smart Card Logon (1.3.6.1.4.1.311.20.2.2).
ii. Any Purpose EKU (2.5.29.37.0).
iii. No EKU set. i.e., this is a (subordinate) CA certificate.

Certificate templates with the following extended key usages AND that allow a requestor to supply the subject name in the request must require manual approval:
i. Client Authentication (1.3.6.1.5.5.7.3.2).
ii. PKINIT Client Authentication (1.3.6.1.5.2.3.4).
iii. Supply in request" setting: VulnerableCertTemplate Properties.

Check Contents

Certificate templates with the following extended key usages AND that allow a requestor to supply the subject name in the request require manual approval. In the AD CS web server properties, select "VulnerableCertTemplate" properties. Verify that "Subject Name" and "Supply in the request" are selected.

If "Subject Name" AND "Supply in the request" are selected and if manual approval is not required, this is a finding.

If the "Supply in Request" is NOT selected, and the Enroll Permissions for the template have been limited to a select group of users/administrators, this is not a finding.

Vulnerability Number

V-269098

Documentable

False

Rule Version

AD.3145_AD

Severity Override Guidance

Certificate templates with the following extended key usages AND that allow a requestor to supply the subject name in the request require manual approval. In the AD CS web server properties, select "VulnerableCertTemplate" properties. Verify that "Subject Name" and "Supply in the request" are selected.

If "Subject Name" AND "Supply in the request" are selected and if manual approval is not required, this is a finding.

If the "Supply in Request" is NOT selected, and the Enroll Permissions for the template have been limited to a select group of users/administrators, this is not a finding.

Check Content Reference

M

Target Key

5407