2.021 - Software certificate installation files must be removed from Windows 2008.

Information

Use of software certificates and their accompanying installation files for end users to access resources is less secure than the use of hardware-based certificates.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Remove any certificate installation files (*.p12 and *.pfx) found on a system.

This does not apply to server-based applications that have a requirement for certificate files or non-certificate installation files with the same extension.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2008_DC_V6R47_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-12, CAT|II, CCI|CCI-000366, Rule-ID|SV-29465r2_rule, STIG-ID|2.021, Vuln-ID|V-15823

Plugin: Windows

Control ID: 9cac7a5354fe9649db1973d05d7c49cdeff793b8ca0706b2e87715ca0fe68285