WN11-PK-000010 - The External Root CA certificates must be installed in the Trusted Root Store on unclassified systems.

Information

To ensure secure websites protected with External Certificate Authority (ECA) server certificates are properly validated, the system must trust the ECA Root CAs. The ECA root certificates will ensure the trust chain is established for server certificates issued from the External CAs. This requirement only applies to unclassified systems.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Install the ECA Root CA certificates on unclassified systems.

ECA Root CA 4

The InstallRoot tool is available on Cyber Exchange at https://cyber.mil/pki-pke/tools-configuration-files. PKI can be found at https://crl.gds.disa.mil/.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_11_V2R2_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2)(a), CAT|II, CCI|CCI-000185, Rule-ID|SV-253428r958448_rule, STIG-ID|WN11-PK-000010, Vuln-ID|V-253428

Plugin: Windows

Control ID: ec009a84bf405c7d79bc8816b5fe19db51e4dff0791a9ff6b7dd38c2bc890806