SV-266165r1024396_rule
V-266165
SRG-NET-000164-ALG-000100
F5BI-AP-300154
CAT I
10
Access Policy:
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Add an "OCSP Auth" with certificate type of "User" and/or a "CRLDP Auth" object in the Access Profile.
Note: To create an OCSP Responder, go to Access >> Authentication >> OCSP Responder.
Note: To create a CRLDP Server object, go to Access >> Authentication >> CRLDP.
6. Add an "OCSP Auth" object in the Access Profile and select an OCSP Responder.
7. Click "Update".
If the BIG-IP appliance does not provide intermediary services for TLS, or application protocols that use TLS (e.g., DNSSEC or HTTPS), this is not applicable.
Access Policy:
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Verify an "OCSP Auth" object is configured in the Access Profile for "User" type or a CRLDP object is configured.
If the BIG-IP appliance is not configured to use OCSP or CRLDP to ensure revoked user credentials are prohibited from establishing an allowed session, this is a finding.
V-266165
False
F5BI-AP-300154
If the BIG-IP appliance does not provide intermediary services for TLS, or application protocols that use TLS (e.g., DNSSEC or HTTPS), this is not applicable.
Access Policy:
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Verify an "OCSP Auth" object is configured in the Access Profile for "User" type or a CRLDP object is configured.
If the BIG-IP appliance is not configured to use OCSP or CRLDP to ensure revoked user credentials are prohibited from establishing an allowed session, this is a finding.
M
5640