Information
The macOS system _MUST_ be configured to block access to users who are no longer authorized (i.e., users with revoked certificates).
To prevent the use of untrusted certificates, the certificates on a smartcard card _MUST_ meet the following criteria: its issuer has a system-trusted certificate, the certificate is not expired, its "valid-after" date is in the past, and it passes Certificate Revocation List (CRL) and Online Certificate Status Protocol (OCSP) checking.
By setting the smartcard certificate trust level to moderate, the system will execute a soft revocation, i.e., if the OCSP/CRL server is unreachable, authentication will still succeed.
NOTE: Before applying this setting, please see the smartcard supplemental guidance.
Solution
This is implemented by a Configuration Profile.
mobileconfig profile info:
com.apple.security.smartcard:
checkCertificateTrust:
2
Item Details
Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION
References: 800-53|IA-2(12), 800-53|IA-5(2), 800-53|IA-5(2)(b), 800-53|IA-5(2)(d), 800-53|SC-17, 800-53|SC-23(5), CCE|CCE-84726-9, CCI|CCI-000186, CCI|CCI-001953, CCI|CCI-001954, CCI|CCI-001991, CCI|CCI-002470, STIG-ID|AOSX-15-001060
Control ID: 1e4c8fb4921a7d1cfb1096cb09aed1877aa91aad55aa94bcd1abd773a6aa6da6