SV-269786r1052487_rule
V-269786
SRG-APP-000175-NDM-000262
OS10-NDM-000480
CAT I
10
Configure the OS10 Switch to validate certificates used for PKI-based authentication using DOD approved OCSP or CRL sources:
OS10(config)#
OS10(config)# crypto security-profile <profile-name>
OS10(config-sec-profile)# ocsp-check <ocsp-url>
OS10(config-sec-profile)# exit
OS10(config)#
Verify the OS10 Switch is configured to validate certificates used for PKI-based authentication using DOD-approved OCSP or CRL resources.
Verify that OSCP validation using the appropriate DOD OCSP responder is enabled in the security profile:
ip ssh server x509v3-authentication security-profile cacpiv-prof
...
crypto security-profile <profile-name>
...
ocsp-check <ocsp-url>
...
If the OS10 Switch is not configured to validate certificates used for PKI-based authentication using DOD approved OCSP or CRL sources, this is a finding.
V-269786
False
OS10-NDM-000480
Verify the OS10 Switch is configured to validate certificates used for PKI-based authentication using DOD-approved OCSP or CRL resources.
Verify that OSCP validation using the appropriate DOD OCSP responder is enabled in the security profile:
ip ssh server x509v3-authentication security-profile cacpiv-prof
...
crypto security-profile <profile-name>
...
ocsp-check <ocsp-url>
...
If the OS10 Switch is not configured to validate certificates used for PKI-based authentication using DOD approved OCSP or CRL sources, this is a finding.
M
5666