SV-222550r508029_rule
V-222550
SRG-APP-000175
APSC-DV-001810
CAT I
10
Design the application to construct a certification path to an accepted trust anchor when using PKI-based authentication.
Review the application documentation, the application architecture and interview the application administrator to identify the method employed by the application for validating certificates.
Review the method to determine if a certification path that includes status information is constructed when certificate validation occurs.
Some applications may utilize underlying OS certificate validation and certificate path building capabilities while others may build the capability into the application itself.
The certification path will include the intermediary certificate CAs along with a status of the CA server's signing certificate and will end at the trusted root anchor.
If the application does not construct a certificate path to an accepted trust anchor, this is a finding.
V-222550
False
APSC-DV-001810
Review the application documentation, the application architecture and interview the application administrator to identify the method employed by the application for validating certificates.
Review the method to determine if a certification path that includes status information is constructed when certificate validation occurs.
Some applications may utilize underlying OS certificate validation and certificate path building capabilities while others may build the capability into the application itself.
The certification path will include the intermediary certificate CAs along with a status of the CA server's signing certificate and will end at the trusted root anchor.
If the application does not construct a certificate path to an accepted trust anchor, this is a finding.
M
4093