Automation Controller must only allow the use of DOD PKI-established certificate authorities for verification of the establishment of protected sessions.
If the >><organizationally defined intermediate certificate file in PEM format>>> does not exist, this is a finding.
If the >><organizationally defined intermediate certificate file in PEM format>>> does not exist, this is a finding.
Fix
For each Automation Controller host, the administrator must:
Download the >><organizationally defined intermediate certificate file in PEM format>>>;
Generate the appropriate /etc/tower/tower.key files, certificates, and CSRs and have the organizationally defined PKI authority issue a certificate signed by the >><organizationally defined intermediate certificate file in PEM format>>>;
Place the signed certificate in /etc/tower/tower.cert.
Place the >><organizationally defined intermediate certificate file in PEM format>>> in /etc/pki/ca-trust/source/anchors.