SV-86183r1_rule
V-71559
SRG-APP-000395-NDM-000310
CAGW-DM-000300
CAT II
10
Configure LDAPS/LDAPS+RADIUS to use LDAPS server certificates for bidirectional authentication that is cryptographically based.
Place the LDAPS server certificate in "/etc/openldap/cacerts".
Set "TLS_REQCERT" to demand in "/etc/openldap/ldap.conf".
Verify the LDAPS server certificate is in "/etc/openldap/cacerts". Verify TLS_REQCERT is set to demand in "/etc/openldap/ldap.conf".
If the LDAPS server certificate is not in "/etc/openldap/cacerts", this is a finding.
If "TLS_REQCERT" is not set to demand in "/etc/openldap/ldap.conf", this is a finding.
V-71559
False
CAGW-DM-000300
Verify the LDAPS server certificate is in "/etc/openldap/cacerts". Verify TLS_REQCERT is set to demand in "/etc/openldap/ldap.conf".
If the LDAPS server certificate is not in "/etc/openldap/cacerts", this is a finding.
If "TLS_REQCERT" is not set to demand in "/etc/openldap/ldap.conf", this is a finding.
M
3051