STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must be configured to use DOD approved OCSP responders or CRLs to validate certificates used for PKI-based authentication.

DISA Rule

SV-266094r1024902_rule

Vulnerability Number

V-266094

Group Title

SRG-APP-000175-NDM-000262

Rule Version

F5BI-DM-300056

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. If ClientCert LDAP is used as the remote authentication type, click "Change".
6. Set "OCSP Responder" IP address to one that is DOD approved.
Note: The OCSP Override option must be set to "on" to view the OCSP Responder value.
7. Click "Finish".

Check Contents

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - ClientCert LDAP", verify the "OCSP Responder" configured is DOD approved
Note: The OCSP Override option must be set to "on" to view the OCSP Responder value.

If the BIG-IP appliance is not configured to use DOD-approved OCSP responders or CRLs to validate certificates used for PKI-based authentication, this is a finding.

Vulnerability Number

V-266094

Documentable

False

Rule Version

F5BI-DM-300056

Severity Override Guidance

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - ClientCert LDAP", verify the "OCSP Responder" configured is DOD approved
Note: The OCSP Override option must be set to "on" to view the OCSP Responder value.

If the BIG-IP appliance is not configured to use DOD-approved OCSP responders or CRLs to validate certificates used for PKI-based authentication, this is a finding.

Check Content Reference

M

Target Key

5639