WG140 - A private web server does not require subscriber certificates as an access control mechanism. - 'AccessSSL Enabled'

Information

Vulnerability Key: V0006531
IA Controls: IATS-1 Token and Certificate Standards, IATS-2 Token and Certificate Standards
Categories: 1.2 PKI
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.5, 8520.2 Public Key Infrastructure (PKI) and Public Key (PK) Enabling
The use of userids and passwords may lead to compromise of the userid and password, thus
providing access to unauthorized individuals. Stronger authentication mechanisms will reduce this risk
by providing additional factors of authentication before access is granted to the system. Per the DoDI
8520.2 all private web servers are required to request a subscriber certificate issued from a DoD
authorized Certificate Authority for authentication to access DoD private web sites.

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8

Plugin: Windows

Control ID: 6373c0bc3bc2ee1c2831863b37f0f5992dc3677c62e7986b830c6fe6dc635447