Digital Certificates
Parent: T2007
Description
CCSDS recommends two forms of credentials: X.509 certificates and protected simple authentication. There are risks for CCSDS systems utilizing credentials if an attacker gains control of the credential-management system and can issue credentials. If a compromised credential management process results, then there is a need to invalidate existing credentials and reissue all credentials. The authenticity of an X.509 certificate is dependent upon the digital signature of the CA attesting to the credential. If the digital signature algorithm used by the CA is of insufficient cryptographic strength, a credential may be spoofed. (Citation: MITRE ATT&CK) Standard/references: (Citation: SRC014)
Mapped SPARTA techniques
No techniques mapped to this control.
Cite as SafeMode Space, space-shield T2007.003.