SV-215608r561297_rule
V-215608
SRG-APP-000401-DNS-000051
WDNS-IA-000011
CAT II
10
Configure local revocation data to be used in the event access to Certificate Authorities is hindered.
Consult with the SA to determine if there is a third-party CRL server being used for certificate revocation lookup.
If there is, verify if a documented procedure is in place to store a copy of the CRL locally (local to the site, as an alternative to querying the actual Certificate Authorities). An example would be an OCSP responder installed at the local site.
If there is no local cache of revocation data, this is a finding.
V-215608
False
WDNS-IA-000011
Consult with the SA to determine if there is a third-party CRL server being used for certificate revocation lookup.
If there is, verify if a documented procedure is in place to store a copy of the CRL locally (local to the site, as an alternative to querying the actual Certificate Authorities). An example would be an OCSP responder installed at the local site.
If there is no local cache of revocation data, this is a finding.
M
4016