Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-217423 | F5BI-DM-000283 | SV-217423r879887_rule | Medium |
Description |
---|
For user certificates, each organization obtains certificates from an approved, shared service provider, as required by OMB policy. For federal agencies operating a legacy public key infrastructure cross-certified with the Federal Bridge Certification Authority at medium assurance or higher, this Certification Authority will suffice. |
STIG | Date |
---|---|
F5 BIG-IP Device Management Security Technical Implementation Guide | 2024-01-26 |
Check Text ( C-18648r290823_chk ) |
---|
Verify the BIG-IP appliance is configured to obtain public key certificates from an appropriate certificate policy through a DoD-approved service provider. Navigate to the BIG-IP System manager >> System >> Device Certificates >> Device Certificate. Verify the device certificate has been obtained from an approved service provider. If the BIG-IP appliance does not obtain its public key certificates from an appropriate certificate policy through a DoD-approved service provider, this is a finding. |
Fix Text (F-18646r290824_fix) |
---|
Configure the BIG-IP appliance to obtain its public key certificates from an appropriate certificate policy through a DoD-approved service provider. |