1. Home
  2. Security Hardening
  3. DISA IIS 10.0 Server V2R1
  4. IIST-SV-000129 – The IIS 10.0 web server must perform RFC 5280-compliant certification path validation.

IIST-SV-000129 – The IIS 10.0 web server must perform RFC 5280-compliant certification path validation.

Details

This check verifies the server certificate is actually a DoD-issued certificate used by the organization being reviewed. This is used to verify the authenticity of the website to the user. If the certificate is not issued by the DoD or if the certificate has expired, then there is no assurance the use of the certificate is valid, and therefore; the entire purpose of using a certificate is compromised.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open the IIS 10.0 Manager.

Click the IIS 10.0 web server name.

Double-click the ‘Server Certificate’ icon.

Import a valid DoD certificate and remove any non-DoD certificates.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Identification and Authentication.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles