Skip to content

[Feature Request] Compliance Setting: "OS must validate certificates for PKI-based authentication by constructing a certification path to an accepted trust anchor" #569

@ferricoxide

Description

@ferricoxide

Is your feature request related to a problem? Please describe.

STIG scans calling out RHEL-09-631010/OL09-00-000900/ALMA-09-039070

Describe the solution you'd like

Per the STIG guidance:

Configure the OS for PKI-based authentication, to validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.

Obtain a valid copy of the DOD root CA file from the PKI CA certificate bundle from cyber.mil and copy the DoD_PKE_CA_chain.pem into the following file:

/etc/sssd/pki/sssd_auth_ca_db.pem

Describe alternatives you've considered

Additional context

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions