DTBI018 - Check for publishers certificate revocation must be enforced.

Information

Check for publisher's certificate revocation options should be enforced to ensure all PKI signed objects are validated.

Solution

In the Internet Explorer Options, on the 'Advanced' tab, scroll down to Security category, and select the 'Check for publisher's certificate revocation' box.

NOTE: Manual entry for the value State, set to REG_DWORD = 65536, may first be required.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Microsoft_IE9_V1R15_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2)(a), CAT|II, Rule-ID|SV-43163r2_rule, STIG-ID|DTBI018, Vuln-ID|V-32808

Plugin: Windows

Control ID: 74663dd09fd4e1bb90bee04862abdc663e3ef3b670556b244ac1b1665ddd567e