Check: JAMF-10-000040
Jamf Pro v10.x EMM STIG:
JAMF-10-000040
(in versions v3 r1 through v1 r1)
Title
When the Jamf Pro EMM server cannot establish a connection to determine the validity of a certificate, the server must not have the option to accept the certificate. (Cat II impact)
Discussion
When a Jamf Pro EMM server accepts an unverified certificate, it may be trusting a malicious actor. For example, messages signed with an invalid certificate may contain links to malware, which could lead to the installation or distribution of that malware on DoD information systems, leading to compromise of DoD sensitive information and other attacks. SFR ID: FIA_X509_EXT.2.2
Check Content
Validate the Jamf Pro EMM server has been configured to not accept a certificate if the certificate cannot be validated. 1. Open the Jamf Pro EMM console. 2. Open "Settings". 3. Select "User-Initiated Enrollment". 4. Under the General tab, verify "Use a third-party signing certificate" is selected. 5. Verify the name and certificate extension of the DoD p12 certificate is listed. If the Jamf Pro EMM server has been not been configured to not accept a certificate if the certificate cannot be validated, this is a finding.
Fix Text
Configure the Jamf Pro EMM server to not accept a certificate if the certificate cannot be validated. 1. Open the Jamf Pro EMM console. 2. Open "Settings". 3. Select "User-Initiated Enrollment". 4. Under the General tab, select "Use a third-party signing certificate". 5. Drag and drop the DoD p12 certificate. 6. Click "Save".
Additional Identifiers
Rule ID: SV-241790r961038_rule
Vulnerability ID: V-241790
Group Title: PP-MDM-412003
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000185 |
For public key-based authentication, validate certificates by constructing and verifying a certification path to an accepted trust anchor including checking certificate status information. |
CCI-000366 |
Implement the security configuration settings. |
CCI-001310 |
Checks the validity of organization-defined information inputs to the system. |
CCI-002450 |
Implement organization-defined types of cryptography for each specified cryptography use. |