UCF STIG Viewer Logo

The DOD Root Certificate is not installed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-57579 DTBF-0001 SV-71989r1_rule Medium
Description
The DOD root certificate will ensure that the trust chain is established for server certificate issued from the DOD CA.
STIG Date
Mozilla Firefox 2017-03-22

Details

Check Text ( C-58411r3_chk )
Procedure:
Use the Options > Advanced > Certificates dialog, and select the View Certificates button. On the Certificate Manager window, select the Authorities tab. Scroll through the Certificate Name list to the U.S. Government heading. Look for the entry for the DoD Root CA 2.
If there is an entry for the DoD Root CA 2, select the entry and then the View button. On the Certificate Viewer window, determine the value of the MD5 Fingerprint field.

Criteria:
If there is no entry for the DoD Root CA 2, then this is a Finding.

If the value of the MD5 Fingerprint field of the DoD Root CA 2 certificate is not:
47:78:92:DB:8A:EC:1B:53:68:F0:1D:00:9C:34:77:5E, then this is a Finding.

If the value of the SHA1 Fingerprint field of the DoD Root CA 2 certificate is not:
8C:94:1B:34:EA:1E:A6:ED:9A:E2:BC:54:CF:68:72:52:B4:C9:B5:61, then this is a Finding.
Fix Text (F-62779r2_fix)
Install the DOD root certificate. In Options > Advanced, under the Certificates tab, click View Certificates.