STIGUI
V-285652CAT II — Medium severitySV-285652r1274311_rule

The Content Analysis System (CAS) must obtain its public key certificates from an appropriate certificate policy through an approved service provider.

Rule version BCAS-ND-001920 · STIG v1 · 2026-09-16

Discussion

For user certificates, each organization obtains certificates from an approved, shared service provider, as required by OMB policy. For federal agencies operating a legacy public key infrastructure cross-certified with the Federal Bridge Certification Authority at medium assurance or higher, this Certification Authority will suffice.

Check

Verify the web certificate is valid and issued by a DoW Certificate Authority (CA) with the following steps:

1. Log on to the CAS Web Management Console with an administrative account. 2. Examine the SSL/TLS certificate currently in use via the web browser’s security/lock icon. 3. Review the "Subject", "Issuer", and "Validity" fields of the certificate.

If the certificate is not valid, is expired, or was not issued by a DoW CA, this is a finding.

Fix

Configure a valid DoW-issued certificate for web management with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "configure terminal". 4. Download and install the DoW-issued PKCS#12 (.pfx) certificate by entering "web-management https download-certificate url http://[URL]/[SERVER].pfx password [PASSWORD]". (Replace [URL] with the address of the host serving the file, [SERVER] with the filename, and [PASSWORD] with the certificate's password.) 5. Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode.

Identifiers

Group ID
V-285652
Group title
SRG-APP-000516-NDM-000344
Rule ID
SV-285652r1274311_rule
Check ID
C-90332r1273073_chk
Fix ID
F-90237r1274310_fix