Information
This policy setting ensures that Public Key Infrastructure (PKI) certificates associated with user accounts are issued by DoD PKI or an approved External Certificate Authority (ECA).
Without proper issuance, certificates issued by an unauthorized Certificate Authority (CA) have limited value in authentication functions.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
Map the user account to PKI certificates using the appropriate User Principal Name (UPN) for the network. See PKE documentation for details.
Impact:
None