GEN008040 - If the system is using LDAP for authentication or account information, the system must verify the LDAP servers certificate has not been revoked.

Information

LDAP can be used to provide user authentication and account information, which are vital to system security. Communication between an LDAP server and a host using LDAP requires authentication.

Solution

Edit '/etc/ldap.conf' and add or set the 'tls_crlcheck' setting to 'all'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2)(a), CAT|II, CCI|CCI-000185, Rule-ID|SV-218694r603259_rule, STIG-ID|GEN008040, STIG-Legacy|SV-63357, STIG-Legacy|V-22558, Vuln-ID|V-218694

Plugin: Unix

Control ID: a030b384f1d19310f4107b95edb10ba95ba4cf246beb68c93eb307d19da676d7