WN10-PK-000010 - The External Root CA certificates must be installed in the Trusted Root Store on unclassified systems.

Information

To ensure secure websites protected with External Certificate Authority (ECA) server certificates are properly validated, the system must trust the ECA Root CAs. The ECA root certificates will ensure the trust chain is established for server certificates issued from the External CAs. This requirement only applies to unclassified systems.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Install the ECA Root CA certificate on unclassified systems.
ECA Root CA 4

The InstallRoot tool is available on Cyber Exchange at https://cyber.mil/pki-pke/tools-configuration-files. Certificate bundles published by the PKI can be found at https://crl.gds.disa.mil/.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_10_V3R2_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2)(a), CAT|II, CCI|CCI-000185, Rule-ID|SV-220904r958448_rule, STIG-ID|WN10-PK-000010, STIG-Legacy|SV-78073, STIG-Legacy|V-63583, Vuln-ID|V-220904

Plugin: Windows

Control ID: cda0f7dd96eb1cb8d376d91ea3c2e31c5dff4da922c83cbe0fbfae40ab71bc66