UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The DOD Root Certificate is not installed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-223179 DTBG010 SV-223179r612236_rule Medium
Description
The DOD root certificate will ensure that the trust chain is established for server certificate issued from the DOD CA.
STIG Date
Mozilla Firefox Security Technical Implementation Guide 2021-06-09

Details

Check Text ( C-24852r531353_chk )
Navigate to Tools >> Options >> Advanced >> Certificates tab >> View Certificates button. On the Certificate Manager window, select the "Authorities" tab. Scroll through the Certificate Name list to the U.S. Government heading. Look for the entries for DoD Root CA 2, DoD Root CA 3, and DoD Root CA 4.

If there are entries for DoD Root CA 2, DoD Root CA 3, and DoD Root CA 4, select them individually.

Click the "View" button.

Verify the publishing organization is "US Government."

If there are no entries for the DoD Root CA 2, DoD Root CA 3, and DoD Root CA 4, this is a finding.

Note: In a Windows environment, use of policy setting "security.enterprise_roots.enabled=true" will point Firefox to the Windows Trusted Root Certification Authority Store, this is not a finding.
Fix Text (F-24840r531354_fix)
Install the DOD root certificates.