Free DISA STIG and SRG Library | Vaulted

V-33626

Servers must use approved DoD certificates.

Finding ID
Exch-2-014
Rule ID
SV-44046r2_rule
Severity
Cat II
CCE
(None)
Group Title
Exch-2-014
CCI
(None)
Target Key
(None)
Documentable
No
Discussion

Server certificates are required for many security features in Exchange; without them the server cannot engage in many forms of secure communication. Failure to implement valid certificates makes it virtually impossible to secure Exchange's communications.

Fix Text

Remove the non-DoD certificate and import the correct DoD certificates.

Check Content

Open the Exchange Management Shell and enter the following command: Get-ExchangeCertificate | Select CertificateDomains, issuer If the value of 'CertificateDomains' does not indicate it is issued by the DoD, this is a finding.