STIGQter STIGQter: STIG Summary: Dell OS10 Switch NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 Dec 2024:

The Dell OS10 Switch must obtain its public key certificates from an appropriate certificate policy through an approved service provider.

DISA Rule

SV-269802r1052489_rule

Vulnerability Number

V-269802

Group Title

SRG-APP-000516-NDM-000344

Rule Version

OS10-NDM-000960

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the OS10 Switch to obtain its public key certificates from an appropriate certificate policy through an approved service provider.

Install CA certificates using the crypto ca-cert install command as shown in the example below.

OS10# crypto ca-cert install
Certificate base file name : DOD_PKE
Paste certificate below.
Include the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- headers.
Enter a blank line to abort this command.
Certificate:
-----BEGIN CERTIFICATE-----
MIID...
...
...=
-----END CERTIFICATE-----

Install as trusted-host certificate? [yes/no]:n
Processing file ...
Installed Root CA certificate
CommonName = ...
IssuerName = ...
OS10#

Check Contents

Determine if the OS10 Switch obtains public key certificates from an appropriate certificate policy through an approved service provider.

Verify the configured CA certificates with the following commands:

OS10# show crypto ca-certs
--------------------------------------
| Locally installed certificates |
--------------------------------------
DOD_PKE.crt
OS10#
OS10# show crypto ca-certs DOD_PKE.crt
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 1 (0x1)
...

If the OS10 Switch does not obtain its public key certificates from an appropriate certificate policy through an approved service provider, this is a finding.

Vulnerability Number

V-269802

Documentable

False

Rule Version

OS10-NDM-000960

Severity Override Guidance

Determine if the OS10 Switch obtains public key certificates from an appropriate certificate policy through an approved service provider.

Verify the configured CA certificates with the following commands:

OS10# show crypto ca-certs
--------------------------------------
| Locally installed certificates |
--------------------------------------
DOD_PKE.crt
OS10#
OS10# show crypto ca-certs DOD_PKE.crt
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 1 (0x1)
...

If the OS10 Switch does not obtain its public key certificates from an appropriate certificate policy through an approved service provider, this is a finding.

Check Content Reference

M

Target Key

5666