Check: SRG-APP-000514-AS-000137
Application Server SRG:
SRG-APP-000514-AS-000137
(in versions v3 r4 through v2 r2)
Title
The application server must use DoD- or CNSS-approved PKI Class 3 or Class 4 certificates. (Cat II impact)
Discussion
Class 3 PKI certificates are used for servers and software signing rather than for identifying individuals. Class 4 certificates are used for business-to-business transactions. Utilizing unapproved certificates not issued or approved by DoD or CNS creates an integrity risk. The application server must utilize approved DoD or CNS Class 3 or Class 4 certificates for software signing and business-to-business transactions.
Check Content
Review the application server configuration to determine if the application server utilizes approved PKI Class 3 or Class 4 certificates. If the application server is not configured to use approved DoD or CNS certificates, this is a finding.
Fix Text
Configure the application server to use DoD- or CNSS-approved Class 3 or Class 4 PKI certificates.
Additional Identifiers
Rule ID: SV-204832r879885_rule
Vulnerability ID: V-204832
Group Title: SRG-APP-000514
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002450 |
The information system implements organization-defined cryptographic uses and type of cryptography required for each use in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards. |
Controls
Number | Title |
---|---|
SC-13 |
Cryptographic Protection |