STIGQter STIGQter: STIG Summary: Riverbed SteelHead CX v8 ALG Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 30 Nov 2015:

The Riverbed Optimization System (RiOS) that provides intermediary services for TLS must validate certificates used for TLS functions by performing RFC 5280-compliant certification path validation.

DISA Rule

SV-77321r1_rule

Vulnerability Number

V-62831

Group Title

SRG-NET-000164-ALG-000100

Rule Version

RICX-AG-000098

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure RiOS to validate certificates used for TLS functions by performing certificate path validation.

Navigate to the device Management Console.
Navigate to Configure >> Optimization >> CRL Management.
Set the checkbox for "Enable Automatic CRL Polling For CAs".
Set the checkbox for "Enable Automatic CRL Polling For Peering CAs".
Click "Apply".
Navigate to the top of the web page and click "Save".

Check Contents

Verify that RiOS is configured to validate certificates used for TLS functions by performing certificate path validation.

Navigate to the device Management Console.
Navigate to Configure >> Optimization >> CRL Management.
Verify that "Enable Automatic CRL Polling For CAs" and "Enable Automatic CRL Polling For Peering CAs" is checked.

If "Enable Automatic CRL Polling For CAs" and/or "Enable Automatic CRL Polling For Peering CAs" is not set, this is a finding.

Vulnerability Number

V-62831

Documentable

False

Rule Version

RICX-AG-000098

Severity Override Guidance

Verify that RiOS is configured to validate certificates used for TLS functions by performing certificate path validation.

Navigate to the device Management Console.
Navigate to Configure >> Optimization >> CRL Management.
Verify that "Enable Automatic CRL Polling For CAs" and "Enable Automatic CRL Polling For Peering CAs" is checked.

If "Enable Automatic CRL Polling For CAs" and/or "Enable Automatic CRL Polling For Peering CAs" is not set, this is a finding.

Check Content Reference

M

Target Key

2929

Comments