SV-253539r1188294_rule
V-253539
SRG-APP-000177-CTR-000465
CNTR-PC-000750
CAT II
10
Navigate to Prisma Cloud Compute Console's >> Manage >> Authentication >> System Certificate tab.
Revocation block: Set "Enable certificate revocation checking" to "On" and click "Save".
In the "Certificate-based authentication to Console" block, import the smart card's issuing CA's chain of trust to the Console CA certificate(s) field. Click "Save".
Click the "Users" tab. (Accounts cannot be edited. They must be removed and recreated correctly.)
Delete account:
- Click the three-dot menu.
- Click "Delete" and confirm "Delete User".
Create a local user account where the local user account name matches the user's x.509 certificate's subjectName or subject alternative name's PrincipalName value:
- Click "+Add user".
Authentication Source = Local
Username = subject alternative name's PrincipalName value
Password = random password that is not given to the user
- Assign Role.
- Click "Save".
Navigate to Prisma Cloud Compute Console's >> Manage >> Authentication >> System Certificate tab.
If not performing direct smart card authentication to the console, this is not a finding.
If performing direct smart card authentication to the console:
Revocation block: If "Enable certificate revocation checking" is set to "Off", this is a finding.
Show Advanced certificate configuration:
- In the "Certificate-based authentication to Console" block, verify the issuing CA(s) of the end users' certificates are within the Console CA certificate(s) field.
- If there is no users' certificates, this is a finding.
Click the "Users" tab.
Review accounts with Authentication method "Local".
If the local user account's name does not match the user's x.509 certificate's subjectName or the subject alternative name's PrincipalName value, this is a finding.
V-253539
False
CNTR-PC-000750
Navigate to Prisma Cloud Compute Console's >> Manage >> Authentication >> System Certificate tab.
If not performing direct smart card authentication to the console, this is not a finding.
If performing direct smart card authentication to the console:
Revocation block: If "Enable certificate revocation checking" is set to "Off", this is a finding.
Show Advanced certificate configuration:
- In the "Certificate-based authentication to Console" block, verify the issuing CA(s) of the end users' certificates are within the Console CA certificate(s) field.
- If there is no users' certificates, this is a finding.
Click the "Users" tab.
Review accounts with Authentication method "Local".
If the local user account's name does not match the user's x.509 certificate's subjectName or the subject alternative name's PrincipalName value, this is a finding.
M
5473