Check: DTOO311 - Office System
Microsoft Office System 2010 STIG:
DTOO311 - Office System
(in versions v1 r12 through v1 r10)
Title
Key Usage Filtering must be allowed. (Cat II impact)
Discussion
This policy setting allows you to filter a list of digital certificates for signing Excel, PowerPoint, and Word documents, based on the Key Usage field. The Key Usage field in a certificate is used to represent a series of basic constraints about the broad types of operations that can be performed with the certificate. Key usage filtering allows you to filter the list of installed certificates that can be used for signing documents. The filtered list will appear when users attempt to select a certificate for digitally signing a document.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing “Key Usage Filtering” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\general Criteria: If the value FilterDigitalSignatureCert is REG_DWORD = 1, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing “Key Usage Filtering” to “Enabled”.
Additional Identifiers
Rule ID: SV-34085r1_rule
Vulnerability ID: V-26629
Group Title: DTOO311 - Key Usage Filtering
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |