SV-266093r1024899_rule
V-266093
SRG-APP-000400-NDM-000313
F5BI-DM-300055
CAT II
10
From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. If ClientCert LDAP is used as the remote authentication type, configure "OCSP Response Max Age" for an organization-defined time period.
Note: The OCSP Override option must be set to "on" to view the OCSP Response Max Age value.
From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - ClientCert LDAP", verify "OCSP Response Max Age" is configured for an organization-defined time period.
Note: The OCSP Override option must be set to "on" to view the OCSP Response Max Age value.
If the BIG-IP appliance is not configured to prohibit the use of cached authenticators after an organization-defined time period, this is a finding.
V-266093
False
F5BI-DM-300055
From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - ClientCert LDAP", verify "OCSP Response Max Age" is configured for an organization-defined time period.
Note: The OCSP Override option must be set to "on" to view the OCSP Response Max Age value.
If the BIG-IP appliance is not configured to prohibit the use of cached authenticators after an organization-defined time period, this is a finding.
M
5639