20.23 Ensure 'Domain controllers have a PKI server certificate' (STIG DC only)

Information

This policy setting ensures that Domain controllers have a server certificate to establish authenticity as part of PKI authentications in the domain.

Domain controllers are part of the chain of trust for PKI authentications. Without the appropriate certificate, the authenticity of the domain controller cannot be verified.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

If no certificate exists, install an approved certificate on the Domain Controller.

Note: The

Certificate Store

can be loaded by executing the

Microsoft Management Console (MMC

) and loading the

Certificates

snap-in (Computer account).

Impact:

Without the appropriate certificate, the authenticity of the domain controller cannot be verified.

See Also

https://workbench.cisecurity.org/benchmarks/18857

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-23(5)

Plugin: Windows

Control ID: e14b1a96ead90c255c4b3fc4e3cd37f9e89c7be570111185100725b378b477f7