SV-237038r639561_rule
V-237038
SRG-NET-000164-ALG-000100
AADC-AG-000042
CAT II
10
If intermediary services for TLS are provided, configure the device to validate certificates used for TLS functions by performing RFC 5280-compliant certification path validation.
The following command configures an authentication-server profile for an Online Certificate Status Protocol (OCSP) server:
authentication-server ocsp [profile-name]
If the ALG does not provide intermediary services for TLS, or application protocols that use TLS (e.g., DNSSEC or HTTPS), this is not applicable.
Verify the ALG validates certificates used for TLS functions by performing RFC 5280-compliant certification path validation.
If the ALG does not validate certificates used for TLS functions by performing RFC 5280-compliant certification path validation, this is a finding.
V-237038
False
AADC-AG-000042
If the ALG does not provide intermediary services for TLS, or application protocols that use TLS (e.g., DNSSEC or HTTPS), this is not applicable.
Verify the ALG validates certificates used for TLS functions by performing RFC 5280-compliant certification path validation.
If the ALG does not validate certificates used for TLS functions by performing RFC 5280-compliant certification path validation, this is a finding.
M
5285