STIGUI
V-284934CAT II — Medium severitySV-284934r1227151_rule

The Cisco SNA appliance must be configured to obtain its public key certificates from an appropriate certificate policy through an approved service provider.

Rule version CSNA-ND-000930 · STIG v1 · 2026-07-08

Discussion

For user certificates, each organization obtains certificates from an approved, shared service provider, as required by OMB policy. For federal agencies operating a legacy public key infrastructure cross-certified with the Federal Bridge Certification Authority at medium assurance or higher, this Certification Authority (CA) will suffice.

Check

Determine if the Cisco SNA appliance obtains public key certificates from an appropriate certificate policy through an approved service provider.

Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Configuration >> Appliance Tab >> SSL/TLS Appliance Identity. Review the TLS certificate to determine if it is issued by a DoW CA.

If the Cisco SNA appliance does not obtain its public key certificates from an appropriate certificate policy through an approved service provider, this is a finding.

Fix

Configure the network device to obtain its public key certificates from an appropriate certificate policy through an approved service provider.

Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Configuration >> Appliance Tab >> SSL/TLS Appliance Identity >> Update Identity >> Generate CSR. Input RSA Key Length. Download CSR >> Submit CSR to DoW CA >> Click Replace Identity >> Apply Settings.

For further details review the SNA SSL/TLS Certificates Guide:

https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/certificates/7_5_3_SSL_TLS_Certificates_for_Managed_Appliances_Guide_DV_1_0.pdf.

Identifiers

Group ID
V-284934
Group title
SRG-APP-000516-NDM-000344
Rule ID
SV-284934r1227151_rule
Check ID
C-89503r1227149_chk
Fix ID
F-89408r1227150_fix