UCF STIG Viewer Logo

Only DoD PKI issued or DoD approved server authentication certificates may be installed on the Work Space of the BlackBerry 10 OS.


Overview

Finding ID Version Rule ID IA Controls Severity
V-38312 BB10-00-000320 SV-50112r2_rule Medium
Description
If unauthorized device authentication certificates are installed on the device, there is the potential that the device may connect to a rogue device or network. Rogue devices can mimic the behavior of authorized equipment to trick the user into providing authentication credentials, which could then in turn be used to compromise DoD information and networks. Restricting device authentication certificates to an authorized list mitigates the risk of attaching to rogue devices and networks.
STIG Date
BlackBerry 10 OS Security Technical Implementation Guide 2014-08-27

Details

Check Text ( C-45859r3_chk )
From the Work Space, navigate to "Settings -> Security and Privacy -> Certificates", and throughout different enterprise certificate stores ("Enterprise Root Certificates", "Enterprise Intermediate Certificates", and "Enterprise Client Certificates"), ensure the certificates listed originated from the BDS server. Certificates not originating from a DoD BDS server are a finding.

NOTE: Certificates in stores other than enterprise certificate stores do not apply.
Fix Text (F-43250r3_fix)
On BlackBerry Device Service, remove the corresponding .pem file from :\\Shared\Certificates\ folder.