| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-MozillaFirefox_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 49D2D4D25D074713FC26932FF295E85D10CCF36A ~~~~~ 'Import Enterprise Roots' is Enabled Path: HKLM:\SOFTWARE\Policies\Mozilla\Firefox\Certificates Name: ImportEnterpriseRoots Value: 0x00000001 (1) Type: REG_DWORD Subject: CN=NSS Root CA 4, OU=Certification Authorities, OU=NSS, O=U.S. Government, C=US Thumbprint: D753369F16C2CF15A9647AAE4F6E2B40E4A28242 NotAfter: 10/11/2041 13:47:15 Subject: CN=NSS Root CA 1, OU=Certification Authorities, OU=NSS, O=U.S. Government, C=US Thumbprint: 4D96A58E74C1D5EC06C018459C3DDE71C0DBEF41 NotAfter: 11/28/2029 22:06:38 Subject: CN=NSS Root CA 2, OU=Certification Authorities, OU=NSS, O=U.S. Government, C=US Thumbprint: 3CEE89598C90AA6F5A3B75FB03E94E111D75B5D9 NotAfter: 10/20/2030 13:29:50 Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-MozillaFirefox_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 6B698F8C848148C6B07A5D38E6DD2B7AECD543CC ~~~~~ 'Import Enterprise Roots' is Enabled Path: HKLM:\SOFTWARE\Policies\Mozilla\Firefox\Certificates Name: ImportEnterpriseRoots Value: 0x00000001 (1) Type: REG_DWORD Subject: CN=NSS Root CA 4, OU=Certification Authorities, OU=NSS, O=U.S. Government, C=US Thumbprint: D753369F16C2CF15A9647AAE4F6E2B40E4A28242 NotAfter: 10/11/2041 13:47:15 Subject: CN=NSS Root CA 5, OU=Certification Authorities, OU=NSS, O=U.S. Government, C=US Thumbprint: 7232A47EB4B80CE23A2A3C3799CCAE0D67B0F143 NotAfter: 09/25/2048 15:12:12 Subject: CN=NSS Root CA 1, OU=Certification Authorities, OU=NSS, O=U.S. Government, C=US Thumbprint: 4D96A58E74C1D5EC06C018459C3DDE71C0DBEF41 NotAfter: 11/28/2029 22:06:38 Subject: CN=NSS Root CA 2, OU=Certification Authorities, OU=NSS, O=U.S. Government, C=US Thumbprint: 3CEE89598C90AA6F5A3B75FB03E94E111D75B5D9 NotAfter: 10/20/2030 13:29:50 Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-MozillaFirefox_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: BE8572CFA995924E1F43FC99182513BCB56D8FFB ~~~~~ 'Import Enterprise Roots' is Enabled Path: HKLM:\SOFTWARE\Policies\Mozilla\Firefox\Certificates Name: ImportEnterpriseRoots Value: 0x00000001 (1) Type: REG_DWORD Subject: CN=DoD Root CA 3, OU=PKI, OU=DoD, O=U.S. Government, C=US Thumbprint: D73CA91102A2204A36459ED32213B467D7CE97FB NotAfter: 12/30/2029 Installed: True Subject: CN=DoD Root CA 4, OU=PKI, OU=DoD, O=U.S. Government, C=US Thumbprint: B8269F25DBD937ECAFD4C35A9838571723F2D026 NotAfter: 7/25/2032 Installed: True Subject: CN=DoD Root CA 5, OU=PKI, OU=DoD, O=U.S. Government, C=US Thumbprint: 4ECB5CC3095670454DA1CBD410FC921F46B8564B NotAfter: 6/14/2041 Installed: True Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-MozillaFirefox_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: BE8572CFA995924E1F43FC99182513BCB56D8FFB ~~~~~ 'Import Enterprise Roots' is Enabled Path: HKLM:\SOFTWARE\Policies\Mozilla\Firefox\Certificates Name: ImportEnterpriseRoots Value: 0x00000001 (1) Type: REG_DWORD Subject: CN=DoD Root CA 3, OU=PKI, OU=DoD, O=U.S. Government, C=US Thumbprint: D73CA91102A2204A36459ED32213B467D7CE97FB NotAfter: 12/30/2029 Installed: True Subject: CN=DoD Root CA 4, OU=PKI, OU=DoD, O=U.S. Government, C=US Thumbprint: B8269F25DBD937ECAFD4C35A9838571723F2D026 NotAfter: 7/25/2032 Installed: True Subject: CN=DoD Root CA 5, OU=PKI, OU=DoD, O=U.S. Government, C=US Thumbprint: 4ECB5CC3095670454DA1CBD410FC921F46B8564B NotAfter: 6/14/2041 Installed: True Comments |
|||||
Check Text
Type "about:preferences#privacy" in the browser window. Scroll down to the bottom and select "View Certificates...". In the Certificate Manager window, select the "Authorities" tab. Scroll through the Certificate Name list to the U.S. Government heading. Look for the entries for DOD Root CA 3, DOD Root CA 4, and DOD Root CA 5. If there are entries for DOD Root CA 3, DOD Root CA 4, and DOD Root CA 5, select them individually. Click "View". Verify the issuer name is "US Government". If there are no entries for the appropriate DOD root certificates, this is a finding. If other AO-approved certificates are used, this is not a finding. If SIPRNet-specific certificates are used, this is not a finding. Note: In a Windows environment, use of policy setting "security.enterprise_roots.enabled=true" will point Firefox to the Windows Trusted Root Certification Authority Store. This is not a finding. It can also be set via the policy Certificates >> ImportEnterpriseRoots, which can be verified via "about:policies".
Fix Text
Install the DOD root certificates. Other AO-approved certificates may also be used. Certificates designed for SIPRNet may be used as appropriate. On Windows, import certificates from the operating system by using Certificates >> Import Enterprise Roots (Certificates) via policy or Group Policy Object (GPO).