STIGQter STIGQter: STIG Summary: Dell OS10 Switch NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 Dec 2024:

The Dell OS10 Switch must be configured to use DOD-approved OCSP responders or CRLs to validate certificates used for PKI-based authentication.

DISA Rule

SV-269786r1052487_rule

Vulnerability Number

V-269786

Group Title

SRG-APP-000175-NDM-000262

Rule Version

OS10-NDM-000480

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the OS10 Switch to validate certificates used for PKI-based authentication using DOD approved OCSP or CRL sources:

OS10(config)#
OS10(config)# crypto security-profile <profile-name>
OS10(config-sec-profile)# ocsp-check <ocsp-url>
OS10(config-sec-profile)# exit
OS10(config)#

Check Contents

Verify the OS10 Switch is configured to validate certificates used for PKI-based authentication using DOD-approved OCSP or CRL resources.

Verify that OSCP validation using the appropriate DOD OCSP responder is enabled in the security profile:

ip ssh server x509v3-authentication security-profile cacpiv-prof
...
crypto security-profile <profile-name>
...
ocsp-check <ocsp-url>
...

If the OS10 Switch is not configured to validate certificates used for PKI-based authentication using DOD approved OCSP or CRL sources, this is a finding.

Vulnerability Number

V-269786

Documentable

False

Rule Version

OS10-NDM-000480

Severity Override Guidance

Verify the OS10 Switch is configured to validate certificates used for PKI-based authentication using DOD-approved OCSP or CRL resources.

Verify that OSCP validation using the appropriate DOD OCSP responder is enabled in the security profile:

ip ssh server x509v3-authentication security-profile cacpiv-prof
...
crypto security-profile <profile-name>
...
ocsp-check <ocsp-url>
...

If the OS10 Switch is not configured to validate certificates used for PKI-based authentication using DOD approved OCSP or CRL sources, this is a finding.

Check Content Reference

M

Target Key

5666