SV-266166r1111861_rule
V-266166
SRG-NET-000230-ALG-000113
F5BI-AP-300155
CAT II
10
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Remove any "On-Demand Cert Auth" agents in the profile.
6. Add a "Client Cert Inspection" object in place of the previous "On Demand Cert Auth" agent.
7. Click "Apply Access Policy".
Note: Since use of this setting represent a risk to the DOD requirement for mutual authentication (see vulnerability discussion), if applications that use this function are mission essential, then AO approval is required, and use must be documented.
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Verify the On-Demand Cert Auth agent is not configured in any part of the profile.
If the On-Demand Cert Auth agent is used in any Access Policy Profile, this is a finding.
V-266166
False
F5BI-AP-300155
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Verify the On-Demand Cert Auth agent is not configured in any part of the profile.
If the On-Demand Cert Auth agent is used in any Access Policy Profile, this is a finding.
M
5640