UCF STIG Viewer Logo

The operating system, for PKI-based authentication must enforce authorized access to the corresponding private key.


Overview

Finding ID Version Rule ID IA Controls Severity
RHEL-06-000390-PNF RHEL-06-000390-PNF RHEL-06-000390-PNF_rule Medium
Description
The cornerstone of the PKI is the private key used to encrypt or digitally sign information. If the private key is stolen, this will lead to the compromise of the authentication and non-repudiation gained through PKI because the attacker can use the private key to digitally sign documents and can pretend to be the authorized user. Both the holders of a digital certificate and the issuing authority must protect the computers, storage devices or whatever they use to keep the private keys.
STIG Date
Red Hat Enterprise Linux 6 Security Technical Implementation Guide 2013-02-05

Details

Check Text ( C-RHEL-06-000390-PNF_chk )
RHEL6 supports this requirement and cannot be configured to be out of compliance. This is a permanent not a finding.
Fix Text (F-RHEL-06-000390-PNF_fix)
This requirement is a permanent not a finding. No fix is required.