Samsung Android must [not accept the certificate] when it cannot establish a connection to determine the validity of a certificate.
DISA Rule
SV-230995r607691_rule
Vulnerability Number
V-230995
Group Title
PP-MDF-302490
Rule Version
KNOX-11-013900
Severity
CAT III
CCI(s)
- CCI-000185 - The information system, for PKI-based authentication, validates certifications by constructing and verifying a certification path to an accepted trust anchor including checking certificate status information.
Weight
10
Fix Recommendation
Implement CC Mode (see requirement KNOX-11-020100).
Check Contents
Verify requirement KNOX-11-020100 (CC Mode) has been implemented.
If CC Mode has not been implemented, this is a finding.
Vulnerability Number
V-230995
Documentable
False
Rule Version
KNOX-11-013900
Severity Override Guidance
Verify requirement KNOX-11-020100 (CC Mode) has been implemented.
If CC Mode has not been implemented, this is a finding.
Check Content Reference
M
Target Key
5247
Comments