STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Oct 2024:

AOS must be configured to use DOD-approved Online Certificate Status Protocol (OCSP) responders or Certificate Revocation Lists (CRLs) to validate certificates used for public key infrastructure (PKI)-based authentication.

DISA Rule

SV-266938r1039835_rule

Vulnerability Number

V-266938

Group Title

SRG-APP-000175-NDM-000262

Rule Version

ARBA-ND-000262

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure AOS using the web interface:

1. Navigate to Configuration >> System >> Certificates tab.
2. Under "Import Certificates", upload the trusted root CA. Provide the Certificate name, upload the certificate file, and select the matching Certificate format.
3. Choose the TrustedCA Certificate type. Click "Submit".
4. Upload the same certificate and select the OCSPResponderCert Certificate type (provide a different friendly name). Click "Submit".
5. Click Pending Changes >> Deploy the Changes.
6. Expand "Revocation Checkpoint". Select the configured trusted root CA.
7. Select OCSP for Revocation method 1.
8. Enter the OCSP server URL in the OCSP URL field (remove "http://").
9. Choose the configured certificate under OCSP responder cert.
10. Choose "Fail-Over" for Server unreachable.
11. Click Submit >> Pending Changes >> Deploy Changes.

Check Contents

Verify the AOS configuration with the following command:
show crypto-local pki rcp

If any configured trusted root certificate authorities are not configured to use OCSP, this is a finding.

Vulnerability Number

V-266938

Documentable

False

Rule Version

ARBA-ND-000262

Severity Override Guidance

Verify the AOS configuration with the following command:
show crypto-local pki rcp

If any configured trusted root certificate authorities are not configured to use OCSP, this is a finding.

Check Content Reference

M

Target Key

5648