WG350 IIS7 - A private web server must have a valid server certificate.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This check verifies the server certificate is actually a DoD-issued certificate used by the organization being reviewed. This is used to verify the authenticity of the web site to the user. If the certificate is not issued by the DoD or if the certificate has expired, then there is no assurance the use of the certificate is valid. The entire purpose of using a certificate is, therefore, compromised.

Solution

1. Open the IIS Manager.
2. Click on the Server name.
3. Double-Click the Server Certificate icon.
4. Import a valid DoD certificate and remove any non-DoD certificates.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-23, CAT|II, Rule-ID|SV-32531r2_rule, STIG-ID|WG350_IIS7, Vuln-ID|V-2263

Plugin: Windows

Control ID: 985e411f0714ce926ba7633ce03826c4b978999c7501115d2c40933db1124448