Information
The system must establish the validity of the user-supplied identity certificate using Online Certificate Status Protocol (OCSP) and/or Certificate Revocation List (CRL) revocation checking.
Satisfies: SRG-APP-000175, SRG-APP-000392, SRG-APP-000401, SRG-APP-000403
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider >> Smart Card Authentication.
Under Smart Card Authentication settings >> Certificate Revocation, click the "Edit" button.
Configure revocation checking per site requirements. OCSP with CRL failover is recommended.
Note: If FIPS mode is enabled on vCenter, OCSP revocation validation may not function and CRL bay be used instead.
By default, both locations are pulled from the cert. CRL location can be overridden in this screen, and local responders can be specified via the sso-config command line tool. Refer to the vSphere documentation for more information.
Item Details
Category: IDENTIFICATION AND AUTHENTICATION
References: 800-53|IA-2(12), 800-53|IA-5(2)(a), 800-53|IA-5(2)(d), 800-53|IA-8(1), CAT|II, CCI|CCI-000185, CCI|CCI-001954, CCI|CCI-001991, CCI|CCI-002010, CCI|CCI-004068, Rule-ID|SV-258919r1015931_rule, STIG-ID|VCSA-80-000080, Vuln-ID|V-258919
Control ID: 59af54e6df0c3d948175bcf32ea0c7148d9604fa66e1cc1584843b64eb49fe38