STIGQter STIGQter: STIG Summary: APACHE 2.2 Site for UNIX Security Technical Implementation Guide Version: 1 Release: 11 Benchmark Date: 25 Jan 2019:

Private web servers must require certificates issued from a DoD-authorized Certificate Authority.

DISA Rule

SV-33019r1_rule

Vulnerability Number

V-6531

Group Title

WG140

Rule Version

WG140 A22

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Edit the httpd.conf file and set the value of SSLVerifyClient to "require".

Check Contents

To view the SSLVerifyClient value enter the following command:

grep "SSLVerifyClient" /usr/local/apache2/conf/httpd.conf.

If the value of SSLVerifyClient is not set to “require”, this is a finding.

Vulnerability Number

V-6531

Documentable

False

Rule Version

WG140 A22

Severity Override Guidance

To view the SSLVerifyClient value enter the following command:

grep "SSLVerifyClient" /usr/local/apache2/conf/httpd.conf.

If the value of SSLVerifyClient is not set to “require”, this is a finding.

Check Content Reference

M

Responsibility

Web Administrator

Target Key

161

Comments