SV-103903r1_rule
V-93817
PP-MDF-991000
KNOX-09-001050
CAT II
10
Configure Samsung Android to enable CRL checking for all apps.
On the MDM console, for the device, in the "Knox certificate" group, configure "revocation check" to "enable for all apps".
Refer to the MDM documentation to determine how to configure revocation checking to "enable for all apps". Some may, for example, allow a wildcard string: "*" (asterisk).
Review device configuration settings to confirm that CRL checking is enabled for all apps.
This procedure is performed on the MDM Administration console only.
On the MDM console, for the device, in the "Knox certificate" group, verify that "revocation check" is configured to "enable for all apps".
If on the MDM console "revocation check" is not configured to "enable for all apps", this is a finding.
V-93817
False
KNOX-09-001050
Review device configuration settings to confirm that CRL checking is enabled for all apps.
This procedure is performed on the MDM Administration console only.
On the MDM console, for the device, in the "Knox certificate" group, verify that "revocation check" is configured to "enable for all apps".
If on the MDM console "revocation check" is not configured to "enable for all apps", this is a finding.
M
3507