STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 5 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Fortinet FortiGate Firewall NDM Security Technical Implementation Guide

V-234198

CAT II (Medium)

The FortiGate device must use DoD-approved Certificate Authorities (CAs) for public key certificates.

Rule ID

SV-234198r961863_rule

STIG

Fortinet FortiGate Firewall NDM Security Technical Implementation Guide

Version

V1R5

CCIs

CCI-000366, CCI-001159

Discussion

For user certificates, each organization obtains certificates from an approved, shared service provider, as required by OMB policy. For federal agencies operating a legacy public key infrastructure cross-certified with the Federal Bridge Certification Authority at medium assurance or higher, this CA will suffice.

Check Content

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click System.
2. Click Certificates.
3. Verify CAs are approved providers.

If the public key certificates are not from an approved service provider, this is a finding.

Fix Text

1. Obtain CA certificate from a DoD-approved provider.
2. Log in to the FortiGate GUI with Super-Admin privilege.
3. Click System.
4. Click Certificates.
5. Click Import in the toolbar.
6. Click CA Certificate.
7. On the Import CA Certificate page, select Type File.
8. Locate the certificate file and upload the certificate file.
9. Click OK to import the certificate.