UCF STIG Viewer Logo

The DOD Root Certificate is not installed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-6318 DTBG010 SV-33373r4_rule Medium
Description
The DOD root certificate will ensure that the trust chain is established for server certificate issued from the DOD CA.
STIG Date
Mozilla Firefox 2018-04-02

Details

Check Text ( C-16602r5_chk )
Navigate to Tools >> Options >> Advanced >> Certificates tab >> View Certificates button. On the Certificate Manager window, select the "Authorities" tab. Scroll through the Certificate Name list to the U.S. Government heading. Look for the entry for the DoD Root CA 2.

If there is an entry for the DoD Root CA 2, select the entry and then the "View" button, and ensure the publishing organization is "US Government."

If there is no entry for the DoD Root CA 2, this is a finding.

NOTE: In a Windows environment, use of policy setting "security.enterprise_roots.enabled=true" will point Firefox to the Windows CA and is allowed.
Fix Text (F-5841r2_fix)
Install the DOD CA 2 root certificate.