STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance providing user authentication intermediary services using PKI-based user authentication must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.

DISA Rule

SV-266154r1024381_rule

Vulnerability Number

V-266154

Group Title

SRG-NET-000345-ALG-000099

Rule Version

F5BI-AP-300054

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Add "OCSP Auth" and/or "CRLDP" object in the Access Profile.
Note: To create an OCSP Responder, go to Access >> Authentication >> OCSP Responder.
Note: To create a CRLDP object, go to Access >> Authentication >> CRLDP.
6. Ensure the fallback branch of these objects goes to a "Deny" ending.
7. Click "Apply Access Policy".

Check Contents

If the BIG-IP appliance does not provide PKI-based user authentication intermediary services, this is not applicable.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Verify an "OSCP Auth" and/or "CRLDP" object is configured in the Access Profile VPE AND that the fallback branch of these objects leads to a "Deny" ending.

If the BIG-IP appliance is not configured to deny access when revocation data is unavailable, this is a finding.

Vulnerability Number

V-266154

Documentable

False

Rule Version

F5BI-AP-300054

Severity Override Guidance

If the BIG-IP appliance does not provide PKI-based user authentication intermediary services, this is not applicable.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Verify an "OSCP Auth" and/or "CRLDP" object is configured in the Access Profile VPE AND that the fallback branch of these objects leads to a "Deny" ending.

If the BIG-IP appliance is not configured to deny access when revocation data is unavailable, this is a finding.

Check Content Reference

M

Target Key

5640