SV-264332r984332_rule
V-264332
SRG-NET-000580
SRG-NET-000580-VPN-002431
CAT II
10
Configure the VPN Gateway to reject user certificates that have been revoked when using DOD PKI for authentication.
Verify the VPN Gateway rejects user certificates that have been revoked when using DOD PKI for authentication.
If the VPN Gateway does not configure OCSP and/or CRL to reject revoked user credentials that are prohibited from establishing an allowed session, this is a finding.
V-264332
False
SRG-NET-000580-VPN-002431
Verify the VPN Gateway rejects user certificates that have been revoked when using DOD PKI for authentication.
If the VPN Gateway does not configure OCSP and/or CRL to reject revoked user credentials that are prohibited from establishing an allowed session, this is a finding.
M
2920