SV-268313r1040899_rule
V-268313
SRG-NET-000345-VPN-002430
ARBA-VN-002430
CAT I
10
Configure AOS using the web interface:
1. Navigate to Configuration >> System >> Certificates tab. Under "Import Certificates", upload the trust root CA.
2. Choose the TrustCA Certificate type. Click "Submit".
3. Upload the same certificate and select the OCSPResponderCert Certificate type (provide a different friendly name). Click "Submit".
4. Click Pending Changes >> Deploy Changes.
5. Expand "Revocation Checkpoint". Select the configured trusted root CA.
6. Select "ocsp" for Revocation method 1. Enter the OCSP server URL in the OCSP URL field (remove "http://").
7. Choose the configured certificate under OCSP responder cert. Click "Submit".
8. Click Pending Changes >> Deploy Changes.
Verify the AOS configuration with the following command:
show crypto-local pki rcp
If any configured trusted root certificate authorities are not configured to use OCSP, this is a finding.
V-268313
False
ARBA-VN-002430
Verify the AOS configuration with the following command:
show crypto-local pki rcp
If any configured trusted root certificate authorities are not configured to use OCSP, this is a finding.
M
5645