Skip to content

Apple iOS/iPadOS 17 must have DOD root and intermediate PKI certificates installed.

An XCCDF Rule

Description

DOD root and intermediate PKI certificates are used to verify the authenticity of PKI certificates of users and web services. If the user is allowed to remove root and intermediate certificates, the user could allow an adversary to falsely sign a certificate in such a way that it could not be detected. Restricting the ability to remove DOD root and intermediate PKI certificates to the administrator mitigates this risk. SFR ID: FMT_MOF_EXT.1.2 #47

ID
SV-259793r943704_rule
Version
AIOS-17-714700
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Install DOD intermediate and root certificates on managed mobile devices using the MDM.