Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-38311 | BB10-00-000310 | SV-50111r2_rule | High |
Description |
---|
If unauthorized software authentication certificates are installed on the device, then the operating system would not block malware signed by the entity that published these certificates. Such malware could be used to obtain sensitive DoD information or to further breach system security. Eliminating unapproved software authentication certificates greatly mitigates the risk of malware passing authentication controls. |
STIG | Date |
---|---|
BlackBerry 10 OS Security Technical Implementation Guide | 2014-08-27 |
Check Text ( C-45858r3_chk ) |
---|
From the Work Space, navigate to "Settings -> Security and Privacy -> Certificates", and throughout different enterprise certificate stores ("Enterprise Root Certificates", "Enterprise Intermediate Certificates", and "Enterprise Client Certificates"), ensure the certificates listed originated from the BDS server. Certificates not originating from a DoD BDS server are a finding. NOTE: Certificates in stores other than enterprise certificate stores do not apply. |
Fix Text (F-43249r3_fix) |
---|
On BlackBerry Device Service, remove the corresponding .pem file from |