SV-243115r719588_rule
V-243115
SRG-APP-000516
VCTR-67-000060
CAT II
10
From the vSphere Client, go to Administration >> Single Sign-On > Configuration >> Smart Card Authentication.
Under Smart card authentication settings >> Certificate revocation, click the "Edit" button.
By default, the PSC will use the CRL from the certificate to check revocation check status.
OCSP with CRL fallback is recommended, but this setting is site specific and should be configured appropriately.
From the vSphere Client, go to Administration >> Single Sign-On >> Configuration >> Smart Card Authentication.
Under Smart card authentication settings >> Certificate revocation, verify that "Revocation check" does not show as disabled.
If "Revocation check" shows as disabled, this is a finding.
V-243115
False
VCTR-67-000060
From the vSphere Client, go to Administration >> Single Sign-On >> Configuration >> Smart Card Authentication.
Under Smart card authentication settings >> Certificate revocation, verify that "Revocation check" does not show as disabled.
If "Revocation check" shows as disabled, this is a finding.
M
5399