STIGQter STIGQter: STIG Summary: Ivanti Connect Secure VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Oct 2025:

The ICS, when utilizing PKI-based authentication, must be configured to validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.

DISA Rule

SV-258590r930458_rule

Vulnerability Number

V-258590

Group Title

SRG-NET-000164-VPN-000560

Rule Version

IVCS-VN-000210

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure status checking on the ICS. The focus for this requirement is on the path, so the installation of the device certificates is not included.

In the ICS Web UI, navigate to System >> Configuration >> Certificates >> Trusted Client CAs.
1. Click the first DOD client CA.
2. Enable "Use OCSP with CRL fallback" under "Client certificate status checking".
3. Repeat these steps for every remaining client certificate CA.

Check Contents

In the ICS Web UI, navigate to System >> Configuration >> Certificates >> Trusted Client CAs.
1. Click the first DOD client CA.
2. Verify the item "Use OCSP with CRL fallback" is selected under the "Client certificate status checking" setting.
3. Check each client certificate CA. Verify the setting "Use OCSP with CRL fallback" is selected.

For PKI-based authentication, if the ICS does not validate certificates by constructing a certification path (which includes revocation status information) to an accepted trust anchor, this is a finding.

Vulnerability Number

V-258590

Documentable

False

Rule Version

IVCS-VN-000210

Severity Override Guidance

In the ICS Web UI, navigate to System >> Configuration >> Certificates >> Trusted Client CAs.
1. Click the first DOD client CA.
2. Verify the item "Use OCSP with CRL fallback" is selected under the "Client certificate status checking" setting.
3. Check each client certificate CA. Verify the setting "Use OCSP with CRL fallback" is selected.

For PKI-based authentication, if the ICS does not validate certificates by constructing a certification path (which includes revocation status information) to an accepted trust anchor, this is a finding.

Check Content Reference

M

Target Key

5559