STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Oct 2024:

AOS, when used as a VPN Gateway and using public key infrastructure (PKI)-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.

DISA Rule

SV-266984r1040891_rule

Vulnerability Number

V-266984

Group Title

SRG-NET-000164-VPN-000560

Rule Version

ARBA-VN-000560

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure AOS using the web interface:

1. Navigate to Configuration >> System >> Certificates tab.
2. Under "Import Certificates", click the plus sign (+) and upload the trusted root CA. Provide the certificate name, upload the certificate file, and select the matching certificate format.
3. Choose the TrustedCA Certificate type.
4. Click Submit >> Pending Changes >> and Deploy Changes.

Check Contents

1. Verify the AOS configuration with the following command:
show crypto-local pki trusted CA

2. Note the name(s) of each trust CA.
show crypto-local pki trustedCA <name>

3. Verify that each trusted CA is a valid DOD PKI CA.

If the trusted CAs are not DOD PKI or no DOD PKI CAs are present, this is a finding.

Vulnerability Number

V-266984

Documentable

False

Rule Version

ARBA-VN-000560

Severity Override Guidance

1. Verify the AOS configuration with the following command:
show crypto-local pki trusted CA

2. Note the name(s) of each trust CA.
show crypto-local pki trustedCA <name>

3. Verify that each trusted CA is a valid DOD PKI CA.

If the trusted CAs are not DOD PKI or no DOD PKI CAs are present, this is a finding.

Check Content Reference

M

Target Key

5645