SV-259371r1212361_rule
V-259371
SRG-APP-000401-DNS-000051
WDNS-22-000043
CAT II
10
Configure local revocation data to be used in the event access to Certificate Authorities is hindered.
Note: This check is not applicable for Windows DNS Servers that host only Active Directory (AD)-integrated zones or for Windows DNS Servers on a classified network.
Consult with the system administrator to determine if a third-party CRL server is being used for certificate revocation lookup.
If there is, determine if a documented procedure is in place to store a copy of the CRL locally (local to the site, as an alternative to querying the actual Certificate Authorities). An example would be an OCSP responder installed at the local site.
If there is no local cache of revocation data, this is a finding.
V-259371
False
WDNS-22-000043
Note: This check is not applicable for Windows DNS Servers that host only Active Directory (AD)-integrated zones or for Windows DNS Servers on a classified network.
Consult with the system administrator to determine if a third-party CRL server is being used for certificate revocation lookup.
If there is, determine if a documented procedure is in place to store a copy of the CRL locally (local to the site, as an alternative to querying the actual Certificate Authorities). An example would be an OCSP responder installed at the local site.
If there is no local cache of revocation data, this is a finding.
M
5576