STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The VPN Gateway must configure OCSP to ensure revoked machine certificates are prohibited from establishing an allowed session.

DISA Rule

SV-264333r984335_rule

Vulnerability Number

V-264333

Group Title

SRG-NET-000580

Rule Version

SRG-NET-000580-VPN-002432

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the VPN Gateway to reject machine certificates that have been revoked when using DOD PKI for authentication.

Check Contents

Verify the VPN Gateway rejects machine certificates that have been revoked when using DOD PKI for authentication.

If the VPN Gateway does not configure OCSP and/or CRL to reject revoked machine credentials that are prohibited from establishing an allowed session, this is a finding.

Vulnerability Number

V-264333

Documentable

False

Rule Version

SRG-NET-000580-VPN-002432

Severity Override Guidance

Verify the VPN Gateway rejects machine certificates that have been revoked when using DOD PKI for authentication.

If the VPN Gateway does not configure OCSP and/or CRL to reject revoked machine credentials that are prohibited from establishing an allowed session, this is a finding.

Check Content Reference

M

Target Key

2920