This is not the latest version of the STIG. This is provided for archival purposes. See the latest STIG.

The web server must provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store.

STIG ID: SRG-APP-000915-WSR-000310  |  SRG: SRG-APP-000915 |  Severity: medium (CAT II)  |  CCI: CCI-004910 |  Vulnerability Id: V-264357

Vulnerability Discussion

A Trusted Platform Module (TPM) is an example of a hardware-protected data store that can be used to protect cryptographic keys.

Check

Verify the web server is configured to provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store.

If the web server is not configured to provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store, this is a finding.

Fix

Configure the web server to provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store.