WG140 IIS7 - A private web-sites authentication mechanism must use client certificates.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

A DoD private web-site must utilize PKI as an authentication mechanism for web users. Information systems residing behind web servers requiring authorization based on individual identity shall use the identity provided by certificate-based authentication to support access control decisions. Not using client certificates allows an attacker unauthenticated access to private web-sites.

Solution

1. Open the IIS Manager.
2. Click the site name under review.
3. Double click the SSL Settings icon.
4. Click Clients Certificate Required button.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2), CAT|II, Rule-ID|SV-32380r4_rule, STIG-ID|WG140_IIS7, Vuln-ID|V-6531

Plugin: Windows

Control ID: f557a022d5fd74bace81ec33c49a20157875b6811bc8341371e6e7d4b83ab6a5