UCF STIG Viewer Logo

Root Certificates Update


Overview

Finding ID Version Rule ID IA Controls Severity
V-15671 5.213 SV-29434r1_rule ECSC-1 Low
Description
This check verifies that Root Certificates will not be updated automatically from the Microsoft site.
STIG Date
Windows 2008 Domain Controller Security Technical Implementation Guide 2013-07-03

Details

Check Text ( C-15315r1_chk )
If the following registry value doesn’t exist or is not configured as specified, this is a finding:

Registry Hive: HKEY_LOCAL_MACHINE
Subkey: \Software\Policies\Microsoft\SystemCertificates\AuthRoot\

Value Name: DisableRootAutoUpdate

Type: REG_DWORD
Value: 1
Fix Text (F-15538r1_fix)
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Internet Communication Management -> Internet Communication settings “Turn off Automatic Root Certificates Update” to “Enabled”.