4.2.9 Ensure 'ocsp.enable' certificate revocation is set to 'true'

Information

Certificate revocation is the process of canceling the digital certificate of the revoked user and keeping track of them.

Enabling certificate revocation prevents use of revoked certificates.

Solution

Add ocsp.enable=true in $JAVA_HOME/jre/lib/security/java.security file.

ocsp.enable=true

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-12

Plugin: Unix

Control ID: 1e0539d68744bc75925e7dee72a1eb1c2809b0e52f448ad8e513f19bffe84eb4