STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Oct 2024:

AOS, when used as a VPN Gateway, must not accept certificates that have been revoked when using PKI for authentication.

DISA Rule

SV-268313r1040899_rule

Vulnerability Number

V-268313

Group Title

SRG-NET-000345-VPN-002430

Rule Version

ARBA-VN-002430

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure AOS using the web interface:

1. Navigate to Configuration >> System >> Certificates tab. Under "Import Certificates", upload the trust root CA.
2. Choose the TrustCA Certificate type. Click "Submit".
3. Upload the same certificate and select the OCSPResponderCert Certificate type (provide a different friendly name). Click "Submit".
4. Click Pending Changes >> Deploy Changes.
5. Expand "Revocation Checkpoint". Select the configured trusted root CA.
6. Select "ocsp" for Revocation method 1. Enter the OCSP server URL in the OCSP URL field (remove "http://").
7. Choose the configured certificate under OCSP responder cert. Click "Submit".
8. Click Pending Changes >> Deploy Changes.

Check Contents

Verify the AOS configuration with the following command:
show crypto-local pki rcp

If any configured trusted root certificate authorities are not configured to use OCSP, this is a finding.

Vulnerability Number

V-268313

Documentable

False

Rule Version

ARBA-VN-002430

Severity Override Guidance

Verify the AOS configuration with the following command:
show crypto-local pki rcp

If any configured trusted root certificate authorities are not configured to use OCSP, this is a finding.

Check Content Reference

M

Target Key

5645