UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The BIG-IP appliance must be configured to obtain its public key certificates from an appropriate certificate policy through a DoD-approved service provider.


Overview

Finding ID Version Rule ID IA Controls Severity
V-60239 F5BI-DM-000283 SV-74669r1_rule Medium
Description
For user certificates, each organization obtains certificates from an approved, shared service provider, as required by OMB policy. For federal agencies operating a legacy public key infrastructure cross-certified with the Federal Bridge Certification Authority at medium assurance or higher, this Certification Authority will suffice.
STIG Date
F5 BIG-IP Device Management 11.x Security Technical Implementation Guide 2019-12-20

Details

Check Text ( C-61167r1_chk )
Verify the BIG-IP appliance is configured to obtain public key certificates from an appropriate certificate policy through a DoD-approved service provider.

Navigate to the BIG-IP System manager >> System >> Device Certificates >> Device Certificate.

Verify the device certificate has been obtained from an approved service provider.

If the BIG-IP appliance does not obtain its public key certificates from an appropriate certificate policy through a DoD-approved service provider, this is a finding.
Fix Text (F-65855r1_fix)
Configure the BIG-IP appliance to obtain its public key certificates from an appropriate certificate policy through a DoD-approved service provider.