STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 5 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to BlackBerry Enterprise Mobility Server 2.x Security Technical Implementation Guide

V-79025

CAT II (Medium)

The BlackBerry Enterprise Mobility Server (BEMS) must be configured to use DoD certificates for SSL.

Rule ID

SV-93731r1_rule

STIG

BlackBerry Enterprise Mobility Server 2.x Security Technical Implementation Guide

Version

V1R3

CCIs

CCI-002470

Discussion

Untrusted Certificate Authorities (CA) can issue certificates, but they may be issued by organizations or individuals that seek to compromise DoD systems or by organizations with insufficient security controls. If the CA used for verifying the certificate is not a DoD-approved CA, trust of this CA has not been established.

Check Content

Verify a DoD SSL certificate has been installed on BEMS as follows:

1. Open the browser.
2. Browse to the BEMS dashboard.
3. Select SSL certificate and view the certificate.
4. Verify the certificate is a DoD certificate (has the DoD CA listed in the certificate).

If the SSL certificate installed on BEMS is not a DoD certificate, this is a finding.

Fix Text

Replace the auto-generated BEMS SSL certificate with a DoD certificate as follows:

1. Generate a CSR request and obtain a certificate from the DoD CA.
2. Import the certificate into the BEMS keystore.
3. Update the certificate passwords in BEMS.