STIGQter STIGQter: STIG Summary: Windows Server 2012/2012 R2 Member Server Security Technical Implementation Guide Version: 2 Release: 17 Benchmark Date: 25 Oct 2019: Software certificate installation files must be removed from Windows 2012/2012 R2.

DISA Rule

SV-53141r4_rule

Vulnerability Number

V-15823

Group Title

Software Certificate Installation Files

Rule Version

WN12-GE-000020

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove any certificate installation files (*.p12 and *.pfx) found on a system.

This does not apply to server-based applications that have a requirement for certificate files, Adobe PreFlight certificate files, or non-certificate installation files with the same extension.

Check Contents

Search all drives for *.p12 and *.pfx files.

If any files with these extensions exist, this is a finding.

This does not apply to server-based applications that have a requirement for certificate files or Adobe PreFlight certificate files. Some applications create files with extensions of .p12 that are not certificate installation files. Removal of non-certificate installation files from systems is not required. These must be documented with the ISSO.

Vulnerability Number

V-15823

Documentable

False

Rule Version

WN12-GE-000020

Severity Override Guidance

Search all drives for *.p12 and *.pfx files.

If any files with these extensions exist, this is a finding.

This does not apply to server-based applications that have a requirement for certificate files or Adobe PreFlight certificate files. Some applications create files with extensions of .p12 that are not certificate installation files. Removal of non-certificate installation files from systems is not required. These must be documented with the ISSO.

Check Content Reference

M

Target Key

2350

Comments