STIGQter STIGQter: STIG Summary: Nutanix Acropolis Application Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

Nutanix AOS must perform RFC 5280-compliant certification path validation.

DISA Rule

SV-279442r1192581_rule

Vulnerability Number

V-279442

Group Title

SRG-APP-000175-AS-000124

Rule Version

NXAC-AS-000038

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Nutanix VM application server to use OSCP for certificate revocation.

Set the OCSP responder URL:

$ ncli authconfig set-certificate-revocation set-ocsp-responder=<ocsp url><ocsp url>

Check Contents

Confirm the Nutanix VM application server has OCSP checking enabled.

Run the following command:

$ ncli authconfig get-client-authentication-config
'Auth Config Status : true'

If "Auth config status" is not set to "true", this is a finding.

Vulnerability Number

V-279442

Documentable

False

Rule Version

NXAC-AS-000038

Severity Override Guidance

Confirm the Nutanix VM application server has OCSP checking enabled.

Run the following command:

$ ncli authconfig get-client-authentication-config
'Auth Config Status : true'

If "Auth config status" is not set to "true", this is a finding.

Check Content Reference

M

Target Key

5729