| Vuln ID | Severity | Asset | STIG | Title | Status | Doc Status | Assigned To | Actions |
|---|---|---|---|---|---|---|---|---|
| V-224842 | CAT II | MONT-VSF-004 | Microsoft Windows Server 2016 Security T... | Software certificate installation files must be re... | Documented Pending Review | |||
Check TextSearch all drives for *.p12 and *.pfx files. If any files with these extensions exist, this is a finding. This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Some applications create files with extensions of .p12 that are not certificate installation files. Removal of non-certificate installation files from systems is not required. These must be documented with the ISSO. Fix TextRemove any certificate installation files (*.p12 and *.pfx) found on a system. Note: This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Finding DetailsEvaluate-STIG 1.2507.5 (Scan-WindowsServer2016_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 6D1B1446FB5CC2634D5EADF74C6B8A5903ECB08C ~~~~~ No .p12 or .pfx certificate files found.
Source: _Reviewed/MONT-VSF-004/Checklist/MONT-VSF-004_WinServer2016_V2R10_20251023-143909.ckl
Scan Date: 2026-01-14T12:57:30.046447
Technology Area: Windows Operating System
|
||||||||
| V-224842 | CAT II | MONT-VSF-003 | Microsoft Windows Server 2016 Security T... | Software certificate installation files must be re... | Documented Pending Review | |||
Check TextSearch all drives for *.p12 and *.pfx files. If any files with these extensions exist, this is a finding. This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Some applications create files with extensions of .p12 that are not certificate installation files. Removal of non-certificate installation files from systems is not required. These must be documented with the ISSO. Fix TextRemove any certificate installation files (*.p12 and *.pfx) found on a system. Note: This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Finding DetailsEvaluate-STIG 1.2507.5 (Scan-WindowsServer2016_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 6D1B1446FB5CC2634D5EADF74C6B8A5903ECB08C ~~~~~ No .p12 or .pfx certificate files found.
Source: _Reviewed/MONT-VSF-003/Checklist/MONT-VSF-003_WinServer2016_V2R10_20251023-143935.ckl
Scan Date: 2026-01-14T12:57:31.534241
Technology Area: Windows Operating System
|
||||||||
| V-224842 | CAT II | MONT-MB-002 | Microsoft Windows Server 2016 Security T... | Software certificate installation files must be re... | Documented Pending Review | |||
Check TextSearch all drives for *.p12 and *.pfx files. If any files with these extensions exist, this is a finding. This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Some applications create files with extensions of .p12 that are not certificate installation files. Removal of non-certificate installation files from systems is not required. These must be documented with the ISSO. Fix TextRemove any certificate installation files (*.p12 and *.pfx) found on a system. Note: This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Finding DetailsEvaluate-STIG 1.2507.5 (Scan-WindowsServer2016_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 6D1B1446FB5CC2634D5EADF74C6B8A5903ECB08C ~~~~~ No .p12 or .pfx certificate files found.
Source: _Reviewed/MONT-MB-002/Checklist/MONT-MB-002_WinServer2016_V2R10_20251023-152736.ckl
Scan Date: 2026-01-14T12:57:33.842838
Technology Area: Windows Operating System
|
||||||||
| V-224842 | CAT II | MONT-DP-001 | Microsoft Windows Server 2016 Security T... | Software certificate installation files must be re... | Documented Pending Review | |||
Check TextSearch all drives for *.p12 and *.pfx files. If any files with these extensions exist, this is a finding. This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Some applications create files with extensions of .p12 that are not certificate installation files. Removal of non-certificate installation files from systems is not required. These must be documented with the ISSO. Fix TextRemove any certificate installation files (*.p12 and *.pfx) found on a system. Note: This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Finding DetailsEvaluate-STIG 1.2507.5 (Scan-WindowsServer2016_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 6D1B1446FB5CC2634D5EADF74C6B8A5903ECB08C ~~~~~ No .p12 or .pfx certificate files found.
Source: _Reviewed/MONT-DP-001/Checklist/MONT-DP-001_WinServer2016_V2R10_20251023-144106.ckl
Scan Date: 2026-01-14T12:57:35.637816
Technology Area: Windows Operating System
|
||||||||
| V-224842 | CAT II | MONT-DC-003 | Microsoft Windows Server 2016 Security T... | Software certificate installation files must be re... | Documented Pending Review | |||
Check TextSearch all drives for *.p12 and *.pfx files. If any files with these extensions exist, this is a finding. This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Some applications create files with extensions of .p12 that are not certificate installation files. Removal of non-certificate installation files from systems is not required. These must be documented with the ISSO. Fix TextRemove any certificate installation files (*.p12 and *.pfx) found on a system. Note: This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Finding DetailsEvaluate-STIG 1.2507.5 (Scan-WindowsServer2016_Checks) was unable to determine a Status but found the below configuration on 10/23/2025: ResultHash: 1E905A685F637BB40DE0CCC74A42DFE14AD3B097 ~~~~~ Certificate .p12 and/or .pfx files: --------------------- File: MONT-DC-003.pfx Path: C:\Temp Created: 06/13/2023 20:57:19
Source: _Reviewed/MONT-DC-003/Checklist/MONT-DC-003_WinServer2016_V2R10_20251023-172220.ckl
Scan Date: 2026-01-14T12:57:37.248886
Technology Area: Windows Operating System
|
||||||||
| V-224842 | CAT II | MONT-DB-002 | Microsoft Windows Server 2016 Security T... | Software certificate installation files must be re... | Documented Pending Review | |||
Check TextSearch all drives for *.p12 and *.pfx files. If any files with these extensions exist, this is a finding. This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Some applications create files with extensions of .p12 that are not certificate installation files. Removal of non-certificate installation files from systems is not required. These must be documented with the ISSO. Fix TextRemove any certificate installation files (*.p12 and *.pfx) found on a system. Note: This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Finding DetailsEvaluate-STIG 1.2507.5 (Scan-WindowsServer2016_Checks) was unable to determine a Status but found the below configuration on 10/23/2025: ResultHash: 0D40248E7448FCD0ECA615A2881C86BAFE70E90B ~~~~~ Certificate .p12 and/or .pfx files: --------------------- File: MONT-DB-002.montford-point.navy.mil.pfx Path: E:\SQL Anywhere 16\Application Certificate Files\DoD Created: 06/21/2023 15:54:54 File: MONTFOR-DB-001.montford-point.navy.mil.pfx Path: E:\SQL Anywhere 16\Backup\SAMMDatabase-20230620161919\DoD Created: 06/20/2023 16:21:04 File: MONTFOR-DB-001.montford-point.navy.mil.pfx Path: E:\SQL Anywhere 16\Backup\SAMMDatabase-20230620212252\DoD Created: 06/20/2023 21:22:56 File: MONT-DB-002.montford-point.navy.mil.pfx Path: E:\SQL Anywhere 16\Backup\SAMMDatabase-20230621155610\DoD Created: 06/21/2023 15:56:15 File: MONT-DB-002.montford-point.navy.mil.pfx Path: E:\SQL Anywhere 16\Backup\SAMMDatabase-20230621160233\DoD Created: 06/21/2023 16:02:36 File: MONT-DB-002.montford-point.navy.mil.pfx Path: E:\SQL Anywhere 16\Backup\SAMMDatabase-20230621161956\DoD Created: 06/21/2023 16:19:59
Source: _Reviewed/MONT-DB-002/Checklist/MONT-DB-002_WinServer2016_V2R10_20251023-144132.ckl
Scan Date: 2026-01-14T12:57:39.082634
Technology Area: Windows Operating System
|
||||||||
| V-224842 | CAT II | MONT-BE-002 | Microsoft Windows Server 2016 Security T... | Software certificate installation files must be re... | Documented Pending Review | |||
Check TextSearch all drives for *.p12 and *.pfx files. If any files with these extensions exist, this is a finding. This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Some applications create files with extensions of .p12 that are not certificate installation files. Removal of non-certificate installation files from systems is not required. These must be documented with the ISSO. Fix TextRemove any certificate installation files (*.p12 and *.pfx) found on a system. Note: This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Finding DetailsEvaluate-STIG 1.2507.5 (Scan-WindowsServer2016_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 6D1B1446FB5CC2634D5EADF74C6B8A5903ECB08C ~~~~~ No .p12 or .pfx certificate files found.
Source: _Reviewed/MONT-BE-002/Checklist/MONT-BE-002_WinServer2016_V2R10_20251023-143943.ckl
Scan Date: 2026-01-14T12:57:41.363810
Technology Area: Windows Operating System
|
||||||||
| V-224842 | CAT II | MONT-AP-002 | Microsoft Windows Server 2016 Security T... | Software certificate installation files must be re... | Documented Pending Review | |||
Check TextSearch all drives for *.p12 and *.pfx files. If any files with these extensions exist, this is a finding. This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Some applications create files with extensions of .p12 that are not certificate installation files. Removal of non-certificate installation files from systems is not required. These must be documented with the ISSO. Fix TextRemove any certificate installation files (*.p12 and *.pfx) found on a system. Note: This does not apply to server-based applications that have a requirement for .p12 certificate files or Adobe PreFlight certificate files. Finding DetailsEvaluate-STIG 1.2507.5 (Scan-WindowsServer2016_Checks) was unable to determine a Status but found the below configuration on 10/23/2025: ResultHash: 2F5A03118F95BE99F7982FCF5690595BB04E2973 ~~~~~ Certificate .p12 and/or .pfx files: --------------------- File: MONTFOR-AP-001.montford-point.navy.mil.p12 Path: E:\SAMM Installers\Tomcat Applications\Backup\SAMM-2018062562431 Created: 06/19/2023 21:59:21 File: Tomcat SAMM Vessel.p12 Path: E:\SAMM Installers\Tomcat Applications\Certificate\Keystore Created: 06/19/2023 21:59:21 File: Tomcat SAMM Vessel.p12 Path: E:\TOMCAT APPLICATIONS\Backup\Keystore-20250319142850 Created: 03/19/2025 14:30:26 File: Tomcat SAMM Vessel.p12 Path: E:\TOMCAT APPLICATIONS\Backup\SAMM-20230621171449 Created: 06/21/2023 17:14:54 File: Tomcat SAMM Vessel.p12 Path: E:\TOMCAT APPLICATIONS\Backup\SAMM-20230621171635 Created: 06/21/2023 17:16:37 File: Tomcat SAMM Vessel.p12 Path: E:\TOMCAT APPLICATIONS\Backup\SAMM-20250319141848 Created: 03/19/2025 14:18:54 File: MONT-AP-002.MONTFORD-POINT.navy.mil.pfx Path: E:\TOMCAT APPLICATIONS\Certificate\DoD Created: 06/21/2023 17:14:55 File: MONT-DB-002.MONTFORD-POINT.navy.mil.pfx Path: E:\TOMCAT APPLICATIONS\Certificate\DoD Created: 06/21/2023 17:16:07 File: Tomcat SAMM Vessel.p12 Path: E:\TOMCAT APPLICATIONS\Certificate\Keystore Created: 05/25/2021 17:03:00 File: emprise.pfx Path: E:\TOMCAT APPLICATIONS\webapps\logbook\WEB-INF\classes\certificates Created: 03/19/2025 14:38:23 File: emprise.pfx Path: E:\TOMCAT APPLICATIONS\webapps\shipslog\WEB-INF\classes\certificates Created: 03/19/2025 14:38:27 File: MONT-AP-002.MONTFORD-POINT.navy.mil.pfx Path: E:\Vol1\SAMM temp staging\Tomcat\Certificate\DoD Created: 03/19/2025 14:22:48 File: MONT-DB-002.MONTFORD-POINT.navy.mil.pfx Path: E:\Vol1\SAMM temp staging\Tomcat\Certificate\DoD Created: 03/19/2025 14:22:48 File: Tomcat SAMM Vessel.p12 Path: E:\Vol1\SAMM temp staging\Tomcat\Certificate\Keystore Created: 03/19/2025 14:22:48 File: intermediate.p12 Path: E:\Vol1\SMIS_APP\Certificates\CA Created: 02/26/2025 18:51:28
Source: _Reviewed/MONT-AP-002/Checklist/MONT-AP-002_WinServer2016_V2R10_20251023-144214.ckl
Scan Date: 2026-01-14T12:57:42.721079
Technology Area: Windows Operating System
|
||||||||