SV-266094r1024902_rule
V-266094
SRG-APP-000175-NDM-000262
F5BI-DM-300056
CAT I
10
From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. If ClientCert LDAP is used as the remote authentication type, click "Change".
6. Set "OCSP Responder" IP address to one that is DOD approved.
Note: The OCSP Override option must be set to "on" to view the OCSP Responder value.
7. Click "Finish".
From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - ClientCert LDAP", verify the "OCSP Responder" configured is DOD approved
Note: The OCSP Override option must be set to "on" to view the OCSP Responder value.
If the BIG-IP appliance is not configured to use DOD-approved OCSP responders or CRLs to validate certificates used for PKI-based authentication, this is a finding.
V-266094
False
F5BI-DM-300056
From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - ClientCert LDAP", verify the "OCSP Responder" configured is DOD approved
Note: The OCSP Override option must be set to "on" to view the OCSP Responder value.
If the BIG-IP appliance is not configured to use DOD-approved OCSP responders or CRLs to validate certificates used for PKI-based authentication, this is a finding.
M
5639