STIGQter STIGQter: STIG Summary: CA API Gateway ALG Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 28 Apr 2017:

The CA API Gateway providing user authentication intermediary services using PKI-based user authentication must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.

DISA Rule

SV-86061r1_rule

Vulnerability Number

V-71437

Group Title

SRG-NET-000345-ALG-000099

Rule Version

CAGW-GW-000640

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Open the CA API Gateway - Policy Manager, select "Tasks" from the main menu, and chose "Manage Certificates".

Click the "Certificate Validation" button and add a Revocation Check Policy in accordance with organizational requirements, making sure to select the "Continue processing if server is unavailable" check box within the policy.

If a policy has already been added, open an existing policy and select the "Continue processing if server is unavailable" check box.

Check Contents

Open the CA API Gateway - Policy Manager, select "Tasks" from the main menu and chose "Manage Certificates".

Click the "Certificate Validation" button and verify there is at least one Policy in the list of Revocation Checking Policies.

Double-click one of the listed policies and verify the "Continue processing if server is unavailable" check box is checked.

If there is no policy listed or the "Continue processing if server is unavailable" check box is not selected within the revocation policy, this is a finding.

Vulnerability Number

V-71437

Documentable

False

Rule Version

CAGW-GW-000640

Severity Override Guidance

Open the CA API Gateway - Policy Manager, select "Tasks" from the main menu and chose "Manage Certificates".

Click the "Certificate Validation" button and verify there is at least one Policy in the list of Revocation Checking Policies.

Double-click one of the listed policies and verify the "Continue processing if server is unavailable" check box is checked.

If there is no policy listed or the "Continue processing if server is unavailable" check box is not selected within the revocation policy, this is a finding.

Check Content Reference

M

Target Key

3049

Comments