SRG-APP-000427 Controls

STIG IDVersionTitleProduct
SRG-APP-000427-DNS-000060V4R2If the DNS server is using SIG(0), the DNS server implementation must only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected transactions.Security Requirements Guide - Domain Name Service
SRG-APP-000427-WSR-000186V4R4The web server must only accept client certificates (user and machine) issued by DOD PKI or DOD-approved PKI Certificate Authorities (CAs).Security Requirements Guide - Web Server