STIGUI
V-285658CAT II — Medium severitySV-285658r1274319_rule

The Content Analysis System (CAS) must be configured to include only approved trust anchors in trust stores or certificate stores managed by the organization.

Rule version BCAS-ND-002020 · STIG v1 · 2026-09-16

Discussion

Public key infrastructure (PKI) certificates are certificates with visibility external to organizational systems and certificates related to the internal operations of systems, such as application-specific time services. In cryptographic systems with a hierarchical structure, a trust anchor is an authoritative source (i.e., a certificate authority [CA]) for which trust is assumed and not derived. A root certificate for a PKI system is an example of a trust anchor. A trust store or certificate store maintains a list of trusted root certificates.

Check

Verify the "browser-trusted-fips" CCL contains only valid and required DoW CAs with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and enter the password. 3. Enter "ssl view ccl browser-trusted-fips". 4. Evaluate the output for the listed CAs.

If the list does not contain valid and required DoW CAs, or if the list contains any CAs that are not documented with the information system security manager (ISSM), this is a finding.

Fix

Configure the "browser-trusted-fips" CCL to contain only approved DoW CA certificates with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable", and then enter the password. 3. Enter "configure terminal". 4. Import the required DoW CA certificate by entering "ssl inline fips ca-certificate [CANAME]" (replace [CANAME] with a descriptive name for the CA being imported) and press "Enter". 5. Copy and paste the base64 PEM data into the window, then press "Enter" and "CTRL + D". (Repeat steps 4 and 5 for all required DoW CA certificates.) 6. Add the newly imported CA to the CCL by entering "ssl edit ccl browser-trusted-fips add [CANAME]". (Replace [CANAME] with the name of the CA that was previously imported.) (Repeat this step for all required DoW CA certificates.) 7. Verify the import succeeded in the CCL by entering "ssl view ccl browser-trusted-fips".

Remove any unauthorized or commercial CAs with the following steps:

1. While still in configuration mode, type "ssl edit ccl browser-trusted-fips remove [CANAME]". (Replace [CANAME] with the name of the unapproved CA identified during verification.) (Repeat this step for any unauthorized CAs.) 2. Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode.

Identifiers

Group ID
V-285658
Group title
SRG-APP-000910-NDM-000300
Rule ID
SV-285658r1274319_rule
Check ID
C-90338r1273619_chk
Fix ID
F-90243r1274319_fix