SV-223872r561402_rule
V-223872
SRG-OS-000066-GPOS-00034
TSS0-CE-000020
CAT II
10
If the certificate is a user or device certificate with a status of TRUST, follow procedures to obtain a new certificate or re-key certificate. If it is an expired CA certificate remove it.
Execute the CA-TSS SAFCRRPT using the following as SYSIN input:
RECORDID(-) DETAIL FIELDS(ISSUER SUBJECT ACTIVE EXPIRE TRUST)
If no certificate information is found, this is not a finding.
NOTE: Certificates are only valid when their Status is TRUST. Therefore, you may ignore certificates with the NOTRUST status during the following checks.
Check the expiration for each certificate with a status of TRUST.
If the expiration date has passed, this is a finding.
V-223872
False
TSS0-CE-000020
Execute the CA-TSS SAFCRRPT using the following as SYSIN input:
RECORDID(-) DETAIL FIELDS(ISSUER SUBJECT ACTIVE EXPIRE TRUST)
If no certificate information is found, this is not a finding.
NOTE: Certificates are only valid when their Status is TRUST. Therefore, you may ignore certificates with the NOTRUST status during the following checks.
Check the expiration for each certificate with a status of TRUST.
If the expiration date has passed, this is a finding.
M
4102