STIGUI
V-286403CAT III — Low severitySV-286403r1256811_rule

Samsung Android 17 must [DoW-restricted selection: Allow the user to choose whether to accept the certificate in these cases, not accept the certificate] when it cannot establish a connection to determine the validity of a certificate.

Rule version KNOX-17-004200 · STIG v1 · 2026-08-07

Discussion

Certificate-based security controls depend on the ability of the system to verify the validity of a certificate. If the MOS were to accept an invalid certificate, it could take unauthorized actions, resulting in unanticipated outcomes. At the same time, if the MOS were to disable functionality when it could not determine the validity of the certificate, this could result in a denial of service. Therefore, the ability to provide exceptions is appropriate to balance the tradeoff between security and functionality. Always accepting certificates when they cannot be determined to be valid is the most extreme exception policy and is not appropriate in the DoW context. Involving an administrator or user in the exception decision mitigates this risk to some degree.

SFR ID: FIA_X509_EXT.2.2/FP for X.509

Check

Verify requirement KNOX-17-009200 (Common Criteria mode) has been implemented.

If "Common Criteria mode" has not been implemented, this is a finding.

Fix

Implement "Common Criteria mode" (refer to requirement KNOX-17-009200).

Identifiers

Group ID
V-286403
Group title
PP-MDF-401390
Rule ID
SV-286403r1256811_rule
Check ID
C-91085r1256283_chk
Fix ID
F-90990r1255858_fix