SV-279277r1170713_rule
V-279277
SRG-APP-000875-NDM-000280
SYME-ND-000860
CAT II
10
1. In the Edge SWG Web UI, navigate to the Configuration tab.
2. Select the "SSL" and "OCSP" area.
3. Select "Add Responder".
4. Under URL, select "from certificate".
5. Check "Issuer CCL" and select the one that matches the HTTPS-console or the SSH-console x.509 CCL.
6. Check "Response CCL" and select the one that matches the HTTPS-console or the SSH-console x.509 CCL.
7. Under "SSL Device Profile", ensure it matches the one in the HTTPS-console.
8. Check "Enable Forwarding". Do not check any of the "Ignore Settings".
9. Click "Apply" and "Save".
1. In the Edge SWG Web UI, navigate to the Configuration tab.
2. Select the "SSL" and "OCSP" areas.
If no OCSP responder is configured, this is a finding.
If the OCSP responder is configured, but the "Issuer CCL" does not match the CCL in the HTTPS-console or the SSH-console x.509 CCL, this is a finding.
If the "Response Cache TTL" is not set for "from OCSP response", this is a finding.
If any of the "Ignore Settings" are checked, this is a finding.
V-279277
False
SYME-ND-000860
1. In the Edge SWG Web UI, navigate to the Configuration tab.
2. Select the "SSL" and "OCSP" areas.
If no OCSP responder is configured, this is a finding.
If the OCSP responder is configured, but the "Issuer CCL" does not match the CCL in the HTTPS-console or the SSH-console x.509 CCL, this is a finding.
If the "Response Cache TTL" is not set for "from OCSP response", this is a finding.
If any of the "Ignore Settings" are checked, this is a finding.
M
5726