STIGQter STIGQter: STIG Summary: Authentication, Authorization, and Accounting Services (AAA) Security Requirements Guide Version: 1 Release: 2 Benchmark Date: 24 Jan 2020:

AAA Services must be configured to not accept certificates that have been revoked for PKI-based authentication.

DISA Rule

SV-95637r1_rule

Vulnerability Number

V-80927

Group Title

SRG-APP-000175-AAA-000580

Rule Version

SRG-APP-000175-AAA-000580

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure AAA Services to not accept certificates that have been revoked for PKI-based authentication.

Check Contents

Verify AAA Services are configured to reflect certificates that have been revoked for PKI-based authentication.

If AAA Services are not configured to reject certificates that have been revoked, this is a finding.

Vulnerability Number

V-80927

Documentable

False

Rule Version

SRG-APP-000175-AAA-000580

Severity Override Guidance

Verify AAA Services are configured to reflect certificates that have been revoked for PKI-based authentication.

If AAA Services are not configured to reject certificates that have been revoked, this is a finding.

Check Content Reference

M

Target Key

3357

Comments