SV-276013r1122689_rule
V-276013
SRG-APP-000219
AXOS-00-000065
CAT I
10
Select the gear icon (System Settings) >> Privacy and Security >> Certificate and Encryption.
Under Certificate Verifications Settings, select "Use OCSP".
Under SSL Trust & CA Settings, select "Use custom certificate" and configure for a DOD PKI (or other AO-approved certificate).
Under Mutual TLS Settings, enable the "Enable mutual TLS" slide bar. Check the "Enforce client certificate validation" box.
Under Encryption Settings, ensure the "Allow legacy SSL cipher suites for adapters" box is unchecked.
Select the gear icon (System Settings) >> Privacy and Security >> Certificate and Encryption.
Under SSL Certificate, if the certificate has not been changed from the self-signed default certificate, unless otherwise approved by the authorizing official (AO), this is a finding.
Under Certificate Verifications Settings, if "Use OCSP" is not selected, this is a finding.
Under SSL Trust & CA Settings, if "Use custom certificate" is not selected and configured for a DOD PKI (or other AO-approved certificate), this is a finding.
Under Mutual TLS Settings, if the "Enable mutual TLS" slide bar is not enabled, and the "Enforce client certificate validation" box is unchecked, this is a finding.
Under Encryption Settings, if the "Allow legacy SSL cipher suites for adapters" is checked, this is a finding.
V-276013
False
AXOS-00-000065
Select the gear icon (System Settings) >> Privacy and Security >> Certificate and Encryption.
Under SSL Certificate, if the certificate has not been changed from the self-signed default certificate, unless otherwise approved by the authorizing official (AO), this is a finding.
Under Certificate Verifications Settings, if "Use OCSP" is not selected, this is a finding.
Under SSL Trust & CA Settings, if "Use custom certificate" is not selected and configured for a DOD PKI (or other AO-approved certificate), this is a finding.
Under Mutual TLS Settings, if the "Enable mutual TLS" slide bar is not enabled, and the "Enforce client certificate validation" box is unchecked, this is a finding.
Under Encryption Settings, if the "Allow legacy SSL cipher suites for adapters" is checked, this is a finding.
M
5710