STIGQter STIGQter: STIG Summary: Web Server Security Requirements Guide Version: 2 Release: 3 Benchmark Date: 26 Apr 2019:

Only authenticated system administrators or the designated PKI Sponsor for the web server must have access to the web servers private key.

DISA Rule

SV-54308r3_rule

Vulnerability Number

V-41731

Group Title

SRG-APP-000176-WSR-000096

Rule Version

SRG-APP-000176-WSR-000096

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the web server to ensure only authenticated and authorized users can access the web server's private key.

Check Contents

If the web server does not have a private key, this is N/A.

Review the web server documentation and deployed configuration to determine whether only authenticated system administrators and the designated PKI Sponsor for the web server can access the web server private key.

If the private key is accessible by unauthenticated or unauthorized users, this is a finding.

Vulnerability Number

V-41731

Documentable

False

Rule Version

SRG-APP-000176-WSR-000096

Severity Override Guidance

If the web server does not have a private key, this is N/A.

Review the web server documentation and deployed configuration to determine whether only authenticated system administrators and the designated PKI Sponsor for the web server can access the web server private key.

If the private key is accessible by unauthenticated or unauthorized users, this is a finding.

Check Content Reference

M

Target Key

2557

Comments