GEN008040 - If using LDAP for auth or account information, the system must check that the LDAP server's certificate has not been revoked.

Information

LDAP can be used to provide user authentication and account information, which are vital to system security. Communication between an LDAP server and a host using LDAP requires authentication.

Solution

Edit '/etc/ldap.conf' and add or set the 'tls_crlcheck' setting to 'all'.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2)(a), CAT|II, CCI|CCI-000185, Group-ID|V-22558, Rule-ID|SV-37634r1_rule, STIG-ID|GEN008040, Vuln-ID|V-22558

Plugin: Unix

Control ID: 7c3a9bd1ffb5d6e82e2cd852a80bedc901f7192e4e01e72228b790aa97889cf0