The BlackBerry Enterprise Mobility Server (BEMS) must be configured to use DoD certificates for SSL.
An XCCDF Rule
Description
<VulnDiscussion>Untrusted Certificate Authorities (CA) can issue certificates, but they may be issued by organizations or individuals that seek to compromise DoD systems or by organizations with insufficient security controls. If the CA used for verifying the certificate is not a DoD-approved CA, trust of this CA has not been established.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-93731r1_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Replace the auto-generated BEMS SSL certificate with a DoD certificate as follows:
1. Generate a CSR request and obtain a certificate from the DoD CA.
2. Import the certificate into the BEMS keystore.
3. Update the certificate passwords in BEMS.