4.2.8 Ensure that CA (Certificate Authority) certificates are used

Information

SSL/TLS certificates are used to establish trust during the secure communications. Certificates can be a simple self-signed cert or can be from a well established or known CA authority.

Using trusted Certificate Authority (CA) signed certificates for TLS communications mitigates against using untrusted or revoked certificates and eliminates warning messages in the browser.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Add non self signed CA certificates as described

here

.

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Unix

Control ID: b452b1dfe17784337b2240b9c3cb3c3d63134418ff08d5fbe4c6a509b3eae854