WG355 IIS6 - A private web site must utilize certificates from a trusted DoD CA.

Information

The use of a DoD PKI certificate ensures clients that the private web site they are connecting to is legitimate, and is an essential part of the DoD defense-in-depth strategy.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the certificate trust list to trust only DoD-approved PKIs (e.g., DoD PKI, DoD ECA, and DoD-approved external partners).

See Also

http://iasecontent.disa.mil/stigs/zip/July2015/U_IIS_6-0_V6R16_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-14206r1_rule, STIG-ID|WG355_IIS6, Vuln-ID|V-13620

Plugin: Windows

Control ID: cc058f55e255043783afe80e7c23c8c2b44c77d9b289a9711ff735765b61688b