WN22-00-000240 - Windows Server 2022 must have software certificate installation files removed.

Information

Use of software certificates and their accompanying installation files for end users to access resources is less secure than the use of hardware-based certificates.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Remove any certificate installation files (*.p12 and *.pfx) found on a system.

Note: This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_Server_2022_V2R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-254261r991589_rule, STIG-ID|WN22-00-000240, Vuln-ID|V-254261

Plugin: Windows

Control ID: 18d2cc8d11e8c5f21f0d78dfea6afaa438acf07afe7a2e7702baef7a7918a4db