Rule version BCAS-ND-001920 · STIG v1 · 2026-09-16
For user certificates, each organization obtains certificates from an approved, shared service provider, as required by OMB policy. For federal agencies operating a legacy public key infrastructure cross-certified with the Federal Bridge Certification Authority at medium assurance or higher, this Certification Authority will suffice.
Verify the web certificate is valid and issued by a DoW Certificate Authority (CA) with the following steps:
1. Log on to the CAS Web Management Console with an administrative account. 2. Examine the SSL/TLS certificate currently in use via the web browser’s security/lock icon. 3. Review the "Subject", "Issuer", and "Validity" fields of the certificate.
If the certificate is not valid, is expired, or was not issued by a DoW CA, this is a finding.
Configure a valid DoW-issued certificate for web management with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "configure terminal". 4. Download and install the DoW-issued PKCS#12 (.pfx) certificate by entering "web-management https download-certificate url http://[URL]/[SERVER].pfx password [PASSWORD]". (Replace [URL] with the address of the host serving the file, [SERVER] with the filename, and [PASSWORD] with the certificate's password.) 5. Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode.