STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The VPN Gateway must configure OCSP to ensure revoked user certificates are prohibited from establishing an allowed session.

DISA Rule

SV-264332r984332_rule

Vulnerability Number

V-264332

Group Title

SRG-NET-000580

Rule Version

SRG-NET-000580-VPN-002431

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the VPN Gateway to reject user certificates that have been revoked when using DOD PKI for authentication.

Check Contents

Verify the VPN Gateway rejects user certificates that have been revoked when using DOD PKI for authentication.

If the VPN Gateway does not configure OCSP and/or CRL to reject revoked user credentials that are prohibited from establishing an allowed session, this is a finding.

Vulnerability Number

V-264332

Documentable

False

Rule Version

SRG-NET-000580-VPN-002431

Severity Override Guidance

Verify the VPN Gateway rejects user certificates that have been revoked when using DOD PKI for authentication.

If the VPN Gateway does not configure OCSP and/or CRL to reject revoked user credentials that are prohibited from establishing an allowed session, this is a finding.

Check Content Reference

M

Target Key

2920