The Juniper router must be configured to obtain its public key certificates from an appropriate certificate policy through an approved service provider.
An XCCDF Rule
Description
For user certificates, each organization obtains certificates from an approved, shared service provider, as required by OMB policy. For federal agencies operating a legacy public key infrastructure cross-certified with the Federal Bridge Certification Authority (CA) at medium assurance or higher, this CA will suffice.
- ID
- SV-217352r991995_rule
- Version
- JUNI-ND-001430
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Step 1. Create a trusted profile and email address to send certificate request to.
[edit security]
set pki ca-profile DODXX_CA ca-identity xxxxx.mil
set pki ca-profile DODXX_CA administrator email-address certadmin@xxxxx.mil