STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must prohibit the use of cached authenticators after eight hours or less.

DISA Rule

SV-266093r1024899_rule

Vulnerability Number

V-266093

Group Title

SRG-APP-000400-NDM-000313

Rule Version

F5BI-DM-300055

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. If ClientCert LDAP is used as the remote authentication type, configure "OCSP Response Max Age" for an organization-defined time period.
Note: The OCSP Override option must be set to "on" to view the OCSP Response Max Age value.

Check Contents

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - ClientCert LDAP", verify "OCSP Response Max Age" is configured for an organization-defined time period.
Note: The OCSP Override option must be set to "on" to view the OCSP Response Max Age value.

If the BIG-IP appliance is not configured to prohibit the use of cached authenticators after an organization-defined time period, this is a finding.

Vulnerability Number

V-266093

Documentable

False

Rule Version

F5BI-DM-300055

Severity Override Guidance

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - ClientCert LDAP", verify "OCSP Response Max Age" is configured for an organization-defined time period.
Note: The OCSP Override option must be set to "on" to view the OCSP Response Max Age value.

If the BIG-IP appliance is not configured to prohibit the use of cached authenticators after an organization-defined time period, this is a finding.

Check Content Reference

M

Target Key

5639