Check: DTOO311 - Office System
Microsoft Office System 2010 STIG:
DTOO311 - Office System
(in version v1 r13)
Title
Key Usage Filtering must be allowed. (Cat II impact)
Discussion
This policy setting allows you to filter a list of digital certificates for signing Excel, PowerPoint, and Word documents, based on the Key Usage field. The Key Usage field in a certificate is used to represent a series of basic constraints about the broad types of operations that can be performed with the certificate. Key usage filtering allows you to filter the list of installed certificates that can be used for signing documents. The filtered list will appear when users attempt to select a certificate for digitally signing a document.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing "Key Usage Filtering" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\general Criteria: If the value FilterDigitalSignatureCert is REG_DWORD = 1, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing "Key Usage Filtering" to "Enabled".
Additional Identifiers
Rule ID: SV-241964r961863_rule
Vulnerability ID: V-241964
Group Title: SRG-APP-000516
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |