UCF STIG Viewer Logo

Only DoD PKI-issued or DoD-approved server authentication certificates may be installed on DoD mobile operating system devices.


Overview

Finding ID Version Rule ID IA Controls Severity
KNOX-07-002100 KNOX-07-002100 KNOX-07-002100_rule Medium
Description
If unauthorized device authentication certificates are installed on the device, there is the potential that the device may connect to a rogue device or network. Rogue devices can mimic the behavior of authorized equipment to trick the user into providing authentication credentials, which could then in turn be used to compromise DoD information and networks. Restricting device authentication certificates to an authorized list mitigates the risk of attaching to rogue devices and networks.
STIG Date
Samsung Knox Android 1.0 STIG 2013-05-03

Details

Check Text ( C-KNOX-07-002100_chk )
This check procedure is performed on both the MDM Administration Console and the Samsung Knox Android device.

Check that the appropriate setting is configured on the MDM server.

For example, on the Fixmo Sentinel Administration Console:
1. Ask the MDM administrator to display the list of server authentication certificates in the "Android Certificate Configuration" rule.
2. Verify only DoD PKI issued or DoD approved server authentication certificates are present (Note: these may include those approved by the local command).

On the Samsung Knox Android device:
1. Open device settings.
2. Select "Security".
3. Select "Trusted credentials".
4. Select the "User" tab.
5. Verify no certificates are listed, or that any that are listed have been authorized.

If there are unapproved device authentication certificates present on the MDM whitelist or on the "User" tab of the "Trusted Credentials" setting in the device's "Security" settings, this is a finding.
Fix Text (F-KNOX-07-002100_fix)
Remove non-approved server authentication certificates from the device.

For example, on the Fixmo Sentinel Administration Console, modify the certificate whitelist so that it only includes DoD PKI issued or DoD approved server authentication certificates in the "Android Certificate Configuration" rule.