STIGUI
V-284734CAT II — Medium severitySV-284734r1240607_rule

Google Android 17 must allow only the administrator (EMM) to install/remove DoW root and intermediate PKI certificates.

Rule version GOOG-17-009800 · STIG v1 · 2026-07-09

Discussion

DoW root and intermediate PKI certificates are used to verify the authenticity of PKI certificates of users and web services. If the user is allowed to remove root and intermediate certificates, the user could allow an adversary to falsely sign a certificate in such a way that it could not be detected. Restricting the ability to remove DoW root and intermediate PKI certificates to the administrator mitigates this risk.

SFR ID: FMT_MOF_EXT.1.2 #47

Check

Review the device configuration to confirm that the user is unable to remove DoW root and intermediate PKI certificates.

On the EMM console:

1. Open "Set user restrictions". 2. Verify that "Disallow config credentials" is toggled to "ON".

On the Google Android 17 device:

1. Open Settings. 2. Tap "Security & privacy". 3. Tap "More security & privacy". 4. Tap "Encryption & credentials". 5. Tap "Trusted credentials". 6. Verify that the user is unable to untrust or remove any work certificates.

If on the Google Android 17 device the user is able to remove certificates, this is a finding.

Fix

Configure Google Android 17 device to prevent a user from removing DoW root and intermediate PKI certificates.

On the EMM console:

1. Open "Set user restrictions". 2. Toggle "Disallow config credentials" to "ON".

Configuration API: DISALLOW_CONFIG_CREDENTIALS

Identifiers

Group ID
V-284734
Group title
PP-MDF-994000
Rule ID
SV-284734r1240607_rule
Check ID
C-89304r1240605_chk
Fix ID
F-89209r1240606_fix