SV-214679r385561_rule
V-214679
SRG-NET-000512
JUSX-VN-000012
CAT I
10
Configure the CA trust point to enable certificate revocation check by referencing a CRL or via OCSP.
Examine the CA trust point defined on the VPN gateway to determine if it references a CRL and that revocation check has been enabled. An alternate mechanism for checking the validity of a certificate is the use of the Online Certificate Status Protocol (OCSP). Unlike CRLs, which provide only periodic certificate status checks, OCSP can provide timely information regarding the status of a certificate.
If revoked certificates are accepted for PKI authentication, this is a finding.
V-214679
False
JUSX-VN-000012
Examine the CA trust point defined on the VPN gateway to determine if it references a CRL and that revocation check has been enabled. An alternate mechanism for checking the validity of a certificate is the use of the Online Certificate Status Protocol (OCSP). Unlike CRLs, which provide only periodic certificate status checks, OCSP can provide timely information regarding the status of a certificate.
If revoked certificates are accepted for PKI authentication, this is a finding.
M
4009