UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Remove Software Certificate Installation Files


Overview

Finding ID Version Rule ID IA Controls Severity
V-15823 2.021 SV-29465r1_rule ECSC-1 Medium
Description
This check verifies that software certificate installation files have been removed from a system.
STIG Date
Windows 2008 Member Server Security Technical Implementation Guide 2015-06-03

Details

Check Text ( C-16140r1_chk )
Search all drives for *.p12 and *.pfx files.

If any files with these extensions exist, then this is a finding.

Documentable Explanation: This does not apply to server-based applications that have a requirement for .p12 certificate files (e.g., Oracle Wallet Manager). Some applications create files with extensions of .p12 that are NOT certificate installation files. Removal from systems of non-certificate installation files are not required. These should be documented with the IAO.
Fix Text (F-15775r1_fix)
Remove any certificate installation files found on a system.

Note: This does not apply to server-based applications that have a requirement for .p12 certificate files (e.g., Oracle Wallet Manager)