SV-269740r1054081_rule
V-269740
SRG-APP-000516
XYLK-20-000244
CAT II
10
1. Obtain DOD root certificate authority (CA)-signed certificate for the domain or generate a certificate using other approved provider.
2. Install the certificate in x509 format at /opt/xylok/certs/cert.crt
3. Restart Xylok: systemctl restart xylok
Verify the Xylok Security Suite is using a valid DOD-issued certification with the following command:
$ openssl x509 -noout -text -in /opt/xylok/certs/cert.crt
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 1 (0x1)
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, O = U.S. Government, OU = DoD, OU = PKI, CN = DoD Root CA 3
Validity
Not Before: Mar 20 18:46:41 2012 GMT
Not After : Dec 30 18:46:41 2029 GMT
Subject: C = US, O = U.S. Government, OU = DoD, OU = PKI, CN = DoD Root CA 3
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
If the Issuer is not an approved authority, this is a finding.
V-269740
False
XYLK-20-000244
Verify the Xylok Security Suite is using a valid DOD-issued certification with the following command:
$ openssl x509 -noout -text -in /opt/xylok/certs/cert.crt
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 1 (0x1)
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, O = U.S. Government, OU = DoD, OU = PKI, CN = DoD Root CA 3
Validity
Not Before: Mar 20 18:46:41 2012 GMT
Not After : Dec 30 18:46:41 2029 GMT
Subject: C = US, O = U.S. Government, OU = DoD, OU = PKI, CN = DoD Root CA 3
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
If the Issuer is not an approved authority, this is a finding.
M
5665