SV-258590r930458_rule
V-258590
SRG-NET-000164-VPN-000560
IVCS-VN-000210
CAT II
10
Configure status checking on the ICS. The focus for this requirement is on the path, so the installation of the device certificates is not included.
In the ICS Web UI, navigate to System >> Configuration >> Certificates >> Trusted Client CAs.
1. Click the first DOD client CA.
2. Enable "Use OCSP with CRL fallback" under "Client certificate status checking".
3. Repeat these steps for every remaining client certificate CA.
In the ICS Web UI, navigate to System >> Configuration >> Certificates >> Trusted Client CAs.
1. Click the first DOD client CA.
2. Verify the item "Use OCSP with CRL fallback" is selected under the "Client certificate status checking" setting.
3. Check each client certificate CA. Verify the setting "Use OCSP with CRL fallback" is selected.
For PKI-based authentication, if the ICS does not validate certificates by constructing a certification path (which includes revocation status information) to an accepted trust anchor, this is a finding.
V-258590
False
IVCS-VN-000210
In the ICS Web UI, navigate to System >> Configuration >> Certificates >> Trusted Client CAs.
1. Click the first DOD client CA.
2. Verify the item "Use OCSP with CRL fallback" is selected under the "Client certificate status checking" setting.
3. Check each client certificate CA. Verify the setting "Use OCSP with CRL fallback" is selected.
For PKI-based authentication, if the ICS does not validate certificates by constructing a certification path (which includes revocation status information) to an accepted trust anchor, this is a finding.
M
5559