WG145 - The private web server does not use an approved DoD certificate validation process. - 'Check W3SVC CertCheckMode'

Information

Vulnerability Key: V0013672
IA Controls: IATS-1 Token and Certificate Standards, IATS-2 Token and Certificate Standards
Categories: 1.2 PKI
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.5
Without the use of a certificate validation process, the site is vulnerable to accepting certificates that
have expired or have been revoked. This would allow unauthorized individuals access to the web
server. This also defeats the purpose of the multi-factor authentication provided by the PKI process.
NOTE: This check reviews the web service as the web sites do not have 'CertCheckMode' enabled.

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5

Plugin: Windows

Control ID: d7b8127250e0c14e0dba816b4005242f93f2d80c44bd36f08c8d2cfa20d553a5