SV-282770r1201607_rule
V-282770
SRG-OS-000775-GPOS-00230
TOSS-05-000080
CAT II
10
Configure TOSS 5 to include only approved trust anchors in trust stores or certificate stores by adding certificates using the following command:
$ sudo cp /path/to/new-ca-cert.pem /etc/pki/ca-trust/source/anchors/
$ sudo /bin/update-ca-trust
Verify TOSS 5 only uses trusted certificates using the following command:
$ sudo trust list --filter=blocklist
type: certificate
label: Explicitly Distrust DigiNotar Root CA
trust: distrusted
category: authority
If the "label" field is not configured with "Explicitly Distrust DigiNotar Root CA", if any other labels are present, the line is commented out, or the line is missing, this is a finding.
V-282770
False
TOSS-05-000080
Verify TOSS 5 only uses trusted certificates using the following command:
$ sudo trust list --filter=blocklist
type: certificate
label: Explicitly Distrust DigiNotar Root CA
trust: distrusted
category: authority
If the "label" field is not configured with "Explicitly Distrust DigiNotar Root CA", if any other labels are present, the line is commented out, or the line is missing, this is a finding.
M
5738