EDGE-00-000030 - Online revocation checks must be performed.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Control whether online revocation checks (OCSP/CRL checks) are required. If Microsoft Edge cannot get revocation status information, these certificates are treated as revoked ('hard-fail').

If this policy is enabled, Microsoft Edge always performs revocation checking for server certificates that successfully validate and are signed by locally installed CA certificates.

Solution

Set the policy value for 'Computer Configuration/Administrative Templates/Microsoft Edge/Specify if online OCSP/CRL checks are required for local trust anchors' to 'enabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Edge_V1R1_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000185, Rule-ID|SV-235747r626523_rule, STIG-ID|EDGE-00-000030, Vuln-ID|V-235747

Plugin: Windows

Control ID: 6ec8ccbfa9efe8a9638ec733d9b94da4550728221da3d39de6c9e141304c870c