Skip to main content
CUI

STIG Rule - xccdf_mil.disa.stig_group_V-254414

xccdf_mil.disa.stig_group_V-254414

xccdf_mil.disa.stig_rule_SV-254414r958448_rule

CAT I

Windows Server 2022 PKI certificates associated with user accounts must be issued by a DoD PKI or an approved External Certificate Authority (ECA).

From: Microsoft Windows Server 2022 Security Technical Implementation Guide (VV2R7R7)

Description

<VulnDiscussion>A PKI implementation depends on the practices established by the Certificate Authority (CA) to ensure the implementation is secure. Without proper practices, the certificates issued by a CA have limited value in authentication functions. Satisfies: SRG-OS-000066-GPOS-00034, SRG-OS-000403-GPOS-00182</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

Check Procedure

No check procedure available.

Fix Text

Map user accounts to PKI certificates using the appropriate User Principal Name (UPN) for the network. See PKE documentation for details.

CCI Reference

CCI-000185
Created
2026-03-12 19:38:14
Last Updated
2026-03-12 19:38:14
CUI