STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance must configure certificate path validation to ensure revoked user credentials are prohibited from establishing an allowed session.

DISA Rule

SV-266165r1024396_rule

Vulnerability Number

V-266165

Group Title

SRG-NET-000164-ALG-000100

Rule Version

F5BI-AP-300154

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Access Policy:
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Add an "OCSP Auth" with certificate type of "User" and/or a "CRLDP Auth" object in the Access Profile.
Note: To create an OCSP Responder, go to Access >> Authentication >> OCSP Responder.
Note: To create a CRLDP Server object, go to Access >> Authentication >> CRLDP.
6. Add an "OCSP Auth" object in the Access Profile and select an OCSP Responder.
7. Click "Update".

Check Contents

If the BIG-IP appliance does not provide intermediary services for TLS, or application protocols that use TLS (e.g., DNSSEC or HTTPS), this is not applicable.

Access Policy:
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Verify an "OCSP Auth" object is configured in the Access Profile for "User" type or a CRLDP object is configured.

If the BIG-IP appliance is not configured to use OCSP or CRLDP to ensure revoked user credentials are prohibited from establishing an allowed session, this is a finding.

Vulnerability Number

V-266165

Documentable

False

Rule Version

F5BI-AP-300154

Severity Override Guidance

If the BIG-IP appliance does not provide intermediary services for TLS, or application protocols that use TLS (e.g., DNSSEC or HTTPS), this is not applicable.

Access Policy:
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Verify an "OCSP Auth" object is configured in the Access Profile for "User" type or a CRLDP object is configured.

If the BIG-IP appliance is not configured to use OCSP or CRLDP to ensure revoked user credentials are prohibited from establishing an allowed session, this is a finding.

Check Content Reference

M

Target Key

5640