TCAT-AS-001640 - Application servers must use NIST-approved or NSA-approved key management technology and processes.

Information

Class 3 PKI certificates are used for servers and software signing rather than for identifying individuals. Class 4 certificates are used for business-to-business transactions. Utilizing unapproved certificates not issued or approved by DoD or CNS creates an integrity risk. The application server must utilize approved DoD or CNS Class 3 or Class 4 certificates for software signing and business-to-business transactions.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Obtain and install the DoD PKI CA certificate bundles by accessing the DoD PKI office website at cyber.mil/pki-pke.

Import the DoD CA certificates.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apache_Tomcat_Application_Server_9_V3R1_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|III, CCI|CCI-002450, Rule-ID|SV-223001r961857_rule, STIG-ID|TCAT-AS-001640, STIG-Legacy|SV-111525, STIG-Legacy|V-102585, Vuln-ID|V-223001

Plugin: Unix

Control ID: 9861e87f8ac769ab28b75cbf42068806777e1920189aa2bcec284c580dc03215