CCI|CCI-000186

Title

For public key-based authentication, enforce authorized access to the corresponding private key.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.12 OL08-00-010100UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.59 APPL-14-001150UnixCIS Apple macOS 14 (Sonoma) STIG v1.0.0 CAT I
1.124 APPL-14-003020UnixCIS Apple macOS 14 (Sonoma) STIG v1.0.0 CAT II
1.242 WN22-SO-000350WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT II
1.242 WN22-SO-000350WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT II
1.345 RHEL-09-611190UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
AIX7-00-003004 - AIX SSH private host key files must have mode 0600 or less permissive.UnixDISA STIG AIX 7.x v3r1
ALMA-09-038850 - For PKI-based authentication, AlmaLinux OS 9 must enforce authorized access to the corresponding private key.UnixDISA Cloud Linux AlmaLinux OS 9 STIG v1r5
AOSX-13-067035 - The macOS system must enable certificate for smartcards.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-14-003002 - The macOS system must enable certificate for smartcards.UnixDISA STIG Apple Mac OSX 10.14 v2r6
APPL-14-001150 - The macOS system must disable password authentication for SSH.UnixDISA Apple macOS 14 Sonoma STIG v2r4
APPL-14-003020 - The macOS system must enforce smart card authentication.UnixDISA Apple macOS 14 Sonoma STIG v2r4
APPL-15-001150 - The macOS system must disable password authentication for SSH.UnixDISA Apple macOS 15 Sequoia STIG v1r6
APPL-15-003020 - The macOS system must enforce smart card authentication.UnixDISA Apple macOS 15 Sequoia STIG v1r6
APPL-26-001150 - The macOS system must disable password authentication for SSH.UnixDISA Apple macOS 26 Tahoe STIG v1r1
APPL-26-003020 - The macOS system must enforce smart card authentication.UnixDISA Apple macOS 26 Tahoe STIG v1r1
APPNET0052 - Encryption keys used for the .NET Strong Name Membership Condition must be protected.WindowsDISA Microsoft DotNet Framework 4.0 STIG v2r7
AS24-U1-000360 - The Apache web server must be configured to use a specified IP address and port.UnixDISA STIG Apache Server 2.4 Unix Server v3r2
AS24-U1-000360 - The Apache web server must be configured to use a specified IP address and port.UnixDISA STIG Apache Server 2.4 Unix Server v3r2 Middleware
AS24-U2-000390 - Only authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key.UnixDISA STIG Apache Server 2.4 Unix Site v2r6
AS24-U2-000390 - Only authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key.UnixDISA STIG Apache Server 2.4 Unix Site v2r6 Middleware
AS24-W2-000390 - Only authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key.WindowsDISA Apache Server 2.4 Windows Site STIG v2r2
AZLX-23-001315 - Amazon Linux 2023, for PKI-based authentication, must enforce authorized access to the corresponding private key.UnixDISA Amazon Linux 2023 STIG v1r2
Big Sur - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
BIND-9X-001140 - The BIND 9.x server private key corresponding to the zone-signing key (ZSK) pair must be the only DNSSEC key kept on a name server that supports dynamic updates.UnixDISA BIND 9.x STIG v3r1
BIND-9X-001150 - The BIND 9.x server signature generation using the key signing key (KSK) must be done offline, using the KSK-private key stored offline.UnixDISA BIND 9.x STIG v3r1
BIND-9X-001180 - The read and write access to a TSIG key file used by a BIND 9.x server must be restricted to only the account that runs the name server software.UnixDISA BIND 9.x STIG v3r1
BIND-9X-001190 - A unique TSIG key used by a BIND 9.x server must be generated for each pair of communicating hosts.UnixDISA BIND 9.x STIG v3r1
BIND-9X-001200 - The TSIG keys used with the BIND 9.x implementation must be owned by a privileged account.UnixDISA BIND 9.x STIG v3r1
BIND-9X-001210 - The TSIG keys used with the BIND 9.x implementation must be group owned by a privileged account.UnixDISA BIND 9.x STIG v3r1
Catalina - Set Smartcard Certificate Trust to HighUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Set Smartcard Certificate Trust to HighUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Set Smartcard Certificate Trust to HighUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Set Smartcard Certificate Trust to ModerateUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
CD12-00-010200 - PostgreSQL must enforce authorized access to all PKI private keys stored/utilized by PostgreSQL.UnixDISA STIG Crunchy Data PostgreSQL OS v3r1
DKER-EE-002380 - The certificate chain used by Universal Control Plane (UCP) client bundles must match what is defined in the System Security Plan (SSP) in Docker Enterprise.UnixDISA STIG Docker Enterprise 2.x Linux/Unix v2r2
DKER-EE-002400 - Docker Enterprise Swarm manager must be run in auto-lock mode.UnixDISA STIG Docker Enterprise 2.x Linux/Unix v2r2
DKER-EE-002410 - Docker Enterprise secret management commands must be used for managing secrets in a Swarm cluster.UnixDISA STIG Docker Enterprise 2.x Linux/Unix v2r2
EP11-00-004600 - The EDB Postgres Advanced Server must enforce authorized access to all PKI private keys stored/utilized by the EDB Postgres Advanced Server.WindowsEDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4
EPAS-00-004600 - The EDB Postgres Advanced Server must enforce authorized access to all PKI private keys stored/used by the EDB Postgres Advanced Server.UnixEnterpriseDB PostgreSQL Advanced Server OS Linux v2r1
GEN005523 - The SSH private host key files must have mode 0600 or less permissive.UnixDISA STIG for Oracle Linux 5 v2r1
JBOS-AS-000320 - The JBoss server must be configured to restrict access to the web servers private key to authenticated system administrators.UnixDISA JBoss Enterprise Application Platform 6.3 STIG v2r6
MADB-10-004100 - MariaDB must enforce authorized access to all PKI private keys stored/used by the DBMS.MySQLDBDISA MariaDB Enterprise 10.x v2r4 DB
MD3X-00-000360 - MongoDB must enforce authorized access to all PKI private keys stored/utilized by MongoDB.UnixDISA STIG MongoDB Enterprise Advanced 3.x v2r3 OS