Audits
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Audits
References
CCI
CCI-000186
CCI
CCI|CCI-000186
Title
For public key-based authentication, enforce authorized access to the corresponding private key.
Reference Item Details
Reference:
CCI - DISA Control Correlation Identifier
Category:
2024
Audit Items
View all Reference Audit Items
Name
Plugin
Audit Name
AIX7-00-003004 - AIX SSH private host key files must have mode 0600 or less permissive.
Unix
DISA STIG AIX 7.x v3r1
AOSX-13-067035 - The macOS system must enable certificate for smartcards.
Unix
DISA STIG Apple Mac OSX 10.13 v2r5
AOSX-14-003002 - The macOS system must enable certificate for smartcards.
Unix
DISA STIG Apple Mac OSX 10.14 v2r6
AOSX-15-001060 - The macOS system must accept and verify Personal Identity Verification (PIV) credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions.
Unix
DISA STIG Apple Mac OSX 10.15 v1r10
AS24-W2-000390 - Only authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key.
Windows
DISA STIG Apache Server 2.4 Windows Site v2r1
Big Sur - Set Smartcard Certificate Trust to Moderate
Unix
NIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Set Smartcard Certificate Trust to Moderate
Unix
NIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Set Smartcard Certificate Trust to Moderate
Unix
NIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Set Smartcard Certificate Trust to Moderate
Unix
NIST macOS Big Sur v1.4.0 - CNSSI 1253
BIND-9X-001110 - The TSIG keys used with the BIND 9.x implementation must be owned by a privileged account.
Unix
DISA BIND 9.x STIG v2r3
BIND-9X-001111 - The TSIG keys used with the BIND 9.x implementation must be group owned by a privileged account.
Unix
DISA BIND 9.x STIG v2r3
BIND-9X-001112 - The read and write access to a TSIG key file used by a BIND 9.x server must be restricted to only the account that runs the name server software.
Unix
DISA BIND 9.x STIG v2r3
BIND-9X-001133 - The BIND 9.x server private key corresponding to the ZSK pair must be the only DNSSEC key kept on a name server that supports dynamic updates.
Unix
DISA BIND 9.x STIG v2r3
BIND-9X-001150 - The BIND 9.x server signature generation using the KSK must be done off-line, using the KSK-private key stored off-line.
Unix
DISA BIND 9.x STIG v2r3
Catalina - Set Smartcard Certificate Trust to High
Unix
NIST macOS Catalina v1.5.0 - All Profiles
Catalina - Set Smartcard Certificate Trust to High
Unix
NIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Set Smartcard Certificate Trust to High
Unix
NIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Set Smartcard Certificate Trust to Moderate
Unix
NIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Set Smartcard Certificate Trust to Moderate
Unix
NIST macOS Catalina v1.5.0 - All Profiles
Catalina - Set Smartcard Certificate Trust to Moderate
Unix
NIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Set Smartcard Certificate Trust to Moderate
Unix
NIST macOS Catalina v1.5.0 - CNSSI 1253
DKER-EE-002400 - Docker Enterprise Swarm manager must be run in auto-lock mode.
Unix
DISA STIG Docker Enterprise 2.x Linux/Unix v2r2
EP11-00-004600 - The EDB Postgres Advanced Server must enforce authorized access to all PKI private keys stored/utilized by the EDB Postgres Advanced Server.
Windows
EDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4
GEN005523 - The SSH private host key files must have mode 0600 or less permissive.
Unix
DISA STIG for Oracle Linux 5 v2r1
JBOS-AS-000320 - The JBoss server must be configured to restrict access to the web servers private key to authenticated system administrators.
Unix
DISA JBoss EAP 6.3 STIG v2r5
MADB-10-004100 - MariaDB must enforce authorized access to all PKI private keys stored/used by the DBMS.
MySQLDB
DISA MariaDB Enterprise 10.x v2r2 DB
MD3X-00-000360 - MongoDB must enforce authorized access to all PKI private keys stored/utilized by MongoDB.
Unix
DISA STIG MongoDB Enterprise Advanced 3.x v2r3 OS
MD7X-00-004100 MongoDB must enforce authorized access to all PKI private keys stored/used by MongoDB.
Unix
DISA MongoDB Enterprise Advanced 7.x STIG v1r1
Monterey - Set Smartcard Certificate Trust to High
Unix
NIST macOS Monterey v1.0.0 - 800-53r5 High
Monterey - Set Smartcard Certificate Trust to High
Unix
NIST macOS Monterey v1.0.0 - All Profiles
Monterey - Set Smartcard Certificate Trust to High
Unix
NIST macOS Monterey v1.0.0 - 800-53r4 High
Monterey - Set Smartcard Certificate Trust to Moderate
Unix
NIST macOS Monterey v1.0.0 - CNSSI 1253
Monterey - Set Smartcard Certificate Trust to Moderate
Unix
NIST macOS Monterey v1.0.0 - 800-53r4 Moderate
Monterey - Set Smartcard Certificate Trust to Moderate
Unix
NIST macOS Monterey v1.0.0 - 800-53r5 Moderate
Monterey - Set Smartcard Certificate Trust to Moderate
Unix
NIST macOS Monterey v1.0.0 - All Profiles
OL08-00-010100 - OL 8, for certificate-based authentication, must enforce authorized access to the corresponding private key.
Unix
DISA Oracle Linux 8 STIG v2r2
RHEL-08-010100 - RHEL 8, for certificate-based authentication, must enforce authorized access to the corresponding private key.
Unix
DISA Red Hat Enterprise Linux 8 STIG v2r1
RHEL-09-611190 - RHEL 9, for PKI-based authentication, must enforce authorized access to the corresponding private key.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
TCAT-AS-000710 - Keystore file must be protected.
Unix
DISA STIG Apache Tomcat Application Server 9 v3r1 Middleware
VCFL-67-000018 - vSphere Client must ensure appropriate permissions are set on the keystore.
Unix
DISA STIG VMware vSphere 6.7 Virgo Client v1r2
VCLD-67-000025 - VAMI must protect the keystore from unauthorized access.
Unix
DISA STIG VMware vSphere 6.7 VAMI-lighttpd v1r3
VCLD-70-000017 - VAMI must protect the keystore from unauthorized access - MIME that invoke OS shell programs disabled.
Unix
DISA STIG VMware vSphere 7.0 VAMI v1r2
VCLD-80-000040 The vCenter VAMI service must restrict access to the web server's private key.
Unix
DISA VMware vSphere 8.0 vCenter Appliance Management Interface (VAMI) STIG v2r1
VCPG-67-000014 - VMware Postgres must enforce authorized access to all PKI private keys.
Unix
DISA STIG VMware vSphere 6.7 PostgreSQL v1r2
VCPG-70-000012 - VMware Postgres must enforce authorized access to all public key infrastructure (PKI) private keys.
Unix
DISA STIG VMware vSphere 7.0 PostgreSQL v1r2
VCRP-67-000007 - The rhttpproxy private key file must be protected from unauthorized access.
Unix
DISA STIG VMware vSphere 6.7 RhttpProxy v1r3
VCRP-70-000005 - The Envoy private key file must be protected from unauthorized access.
Unix
DISA STIG VMware vSphere 7.0 RhttpProxy v1r1
WDNS-IA-000006 - The Windows 2012 DNS Server must be configured to enforce authorized access to the corresponding private key.
Windows
DISA Microsoft Windows 2012 Server DNS STIG v2r7
WDNS-IA-000008 - The Windows 2012 DNS Server permissions must be set so that the key file can only be read or modified by the account that runs the name server software.
Windows
DISA Microsoft Windows 2012 Server DNS STIG v2r7
WDNS-IA-000009 - The private key corresponding to the ZSK must only be stored on the name server that does support dynamic updates.
Windows
DISA Microsoft Windows 2012 Server DNS STIG v2r7