SV-258620r997515_rule
V-258620
SRG-APP-000175-NDM-000262
IVCS-NM-000500
CAT I
10
In the ICS Web UI, navigate to System >> Configuration >> Certificates >> Trusted Client CAs.
1. Click the first DOD client CA.
2. Set the item to "Use OCSP with CRL fallback" under "Client certificate status checking".
3. Repeat these steps for every other client certificate CA.
In the ICS Web UI, navigate to System >> Configuration >> Certificates >> Trusted Client CAs.
1. Click the first DOD client CA.
2. Verify the item "Use OCSP with CRL fallback" is selected under the "Client certificate status checking" setting.
3. Check each other client certificate CA. Verify the setting "Use OCSP with CRL fallback" is selected.
If the ICS is not configured to use DOD approved OCSP responders or CRLs to validate certificates used for PKI-based authentication, this is a finding.
V-258620
False
IVCS-NM-000500
In the ICS Web UI, navigate to System >> Configuration >> Certificates >> Trusted Client CAs.
1. Click the first DOD client CA.
2. Verify the item "Use OCSP with CRL fallback" is selected under the "Client certificate status checking" setting.
3. Check each other client certificate CA. Verify the setting "Use OCSP with CRL fallback" is selected.
If the ICS is not configured to use DOD approved OCSP responders or CRLs to validate certificates used for PKI-based authentication, this is a finding.
M
5558