Check: BEMS-03-013600
BlackBerry Enterprise Mobility Server 3.x STIG:
BEMS-03-013600
(in versions v1 r2 through v1 r1)
Title
The BlackBerry Enterprise Mobility Server (BEMS) must be configured to use DOD certificates for SSL. (Cat II impact)
Discussion
Untrusted Certificate Authorities (CA) can issue certificates, but they may be issued by organizations or individuals that seek to compromise DOD systems or by organizations with insufficient security controls. If the CA used for verifying the certificate is not a DOD-approved CA, trust of this CA has not been established.
Check Content
Verify a DOD SSL certificate has been installed on BEMS as follows: 1. Open the browser. 2. Browse to the BEMS dashboard. 3. Select SSL certificate and view the certificate. 4. Verify the certificate is a DOD certificate (has the DOD CA listed in the certificate). If the SSL certificate installed on BEMS is not a DOD certificate, this is a finding.
Fix Text
Replace the auto-generated BEMS SSL certificate with a DOD certificate as follows: 1. Generate a CSR request and obtain a certificate from the DOD CA. 2. Import the certificate into the BEMS keystore. 3. Update the certificate passwords in BEMS.
Additional Identifiers
Rule ID: SV-254717r879887_rule
Vulnerability ID: V-254717
Group Title: SRG-APP-000516-AS-000237
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002470 |
The information system only allows the use of organization-defined certificate authorities for verification of the establishment of protected sessions. |
Controls
Number | Title |
---|---|
SC-23 (5) |
Allowed Certificate Authorities |