SV-273207r1098888_rule
V-273207
SRG-APP-000427
OKTA-APP-001920
CAT II
10
From the Admin Console:
1. Go to Security >> Identity Providers.
2. Click "Add identity provider."
3. Click "Smart Card IdP". Click "Next".
4. Enter the name of the identity provider.
5. Build a certificate chain:
- Click "Browse" to open a file explorer. Select the certificate file to add and click "Open".
- To add another certificate, click "Add Another" and repeat step 1.
- Click "Build certificate chain". On success, the chain and its certificates are shown. If the build failed, correct any issues and try again.
- Click "Reset certificate chain" if replacing the current chain with a new one.
6. In "IdP username", select the "idpuser.subjectAltNameUpn" attribute. This is the attribute that stores the Electronic Data Interchange Personnel Identifier (EDIPI) on the CAC.
7. In the "Match Against" field, select the Okta Profile Attribute in which the EDIPI is to be stored.
From the Admin Console:
1. Select Security >> Identity Providers (IdPs).
2. Review the list of IdPs with "Type" as "Smart Card".
If the IdP is not listed as "Active", this is a finding.
3. Select Actions >> Configure.
4. Under "Certificate chain", verify the certificate is from a DOD-approved CA.
If the certificate is not from a DOD-approved CA, this is a finding.
V-273207
False
OKTA-APP-001920
From the Admin Console:
1. Select Security >> Identity Providers (IdPs).
2. Review the list of IdPs with "Type" as "Smart Card".
If the IdP is not listed as "Active", this is a finding.
3. Select Actions >> Configure.
4. Under "Certificate chain", verify the certificate is from a DOD-approved CA.
If the certificate is not from a DOD-approved CA, this is a finding.
M
5694