FireEye - Email encryption certificates are verified

Information

If TLS encryption is used for email communication then the certificate should be verified to provide assurance it was issued by a trusted CA. An unverified certificate could be duplicated and spoofed.

Solution

Edit the configuration and modify this line:\n

email ssl cert-verify

Item Details

Audit Name: TNS FireEye

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2)(a)

Plugin: FireEye

Control ID: 1c844d5a9fa76643650b70589e31ff5cb37d8b80f0d17349db73ab7c3e64f70d