STIGUI
V-286488CAT II — Medium severitySV-286488r1274141_rule

WTM must obtain its public key certificates from an appropriate certificate policy through an approved service provider.

Rule version AWTM-NM-000031 · STIG v1 · 2026-09-14

Discussion

For user certificates, each organization obtains certificates from an approved, shared service provider, as required by OMB policy. For federal agencies operating a legacy public key infrastructure cross-certified with the Federal Bridge Certification Authority at medium assurance or higher, this certification authority will suffice.

Satisfies: SRG-APP-000516-NDM-000344, SRG-APP-000910-NDM-000300

Check

1. Log in to the SSH CLI. 2. Enter "show crypto installed-tls-certificate". 3. Verify a DoW certificate is configured.

If "crypto installed-tls-certificate contents" is absent or does not contain a valid DoW CA Issuer, this is a finding.

Fix

1. Log in to the SSH CLI. 2. Enter "configure terminal". 3. Enter "tls-import-ca-certificate certificate-name <CA NAME> certificate-data" and press "Enter". 4. Paste the certificate data from the DoW CA certificate and press enter. 5. Repeat these steps for the root and issuing CA certificate for the WTM. 6. Enter "tls-import-certificate private-key" and press enter. 7. Paste in the contents of the private TLS key and press enter. 8. If it is not encrypted, press enter without entering a password. 9. Once promoted for the certificate, paste it and press enter. 10. Enter commit, accept the warnings, and press enter. The system will need to be rebooted.

Identifiers

Group ID
V-286488
Group title
SRG-APP-000516-NDM-000344
Rule ID
SV-286488r1274141_rule
Check ID
C-91170r1273743_chk
Fix ID
F-91075r1274140_fix