Audits
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Audits
References
CCI
CCI-004068
CCI
CCI|CCI-004068
Title
For public key-based authentication, implement a local cache of revocation data to support path discovery and validation.
Reference Item Details
Reference:
CCI - DISA Control Correlation Identifier
Category:
2024
Audit Items
View all Reference Audit Items
Name
Plugin
Audit Name
AIX7-00-002110 - AIX must setup SSH daemon to disable revoked public keys.
Unix
DISA STIG AIX 7.x v3r1
APPL-14-001060 - The macOS system must set smart card certificate trust to moderate.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-15-001060 - The macOS system must set smart card certificate trust to moderate.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r1
CASA-VN-000130 - The Cisco ASA must be configured to not accept certificates that have been revoked when using PKI for authentication.
Cisco
DISA STIG Cisco ASA VPN v2r2
JUEX-NM-000640 - The Juniper EX switch must be configured to use an authentication server for the purpose of authenticating users prior to granting administrative access.
Juniper
DISA Juniper EX Series Network Device Management v2r2
JUSX-DM-000095 - The Juniper SRX Services Gateway must be configured to use an authentication server to centrally manage authentication and logon settings for remote and nonlocal access.
Juniper
DISA Juniper SRX Services Gateway NDM v3r2
JUSX-DM-000105 - The Juniper SRX Services Gateway must use DOD-approved PKI rather than proprietary or self-signed device certificates.
Juniper
DISA Juniper SRX Services Gateway NDM v3r2
OL08-00-010090 - OL 8, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
Unix
DISA Oracle Linux 8 STIG v2r2
PANW-NM-000110 - The Palo Alto Networks security platform must accept and verify Personal Identity Verification (PIV) credentials
Palo_Alto
DISA STIG Palo Alto NDM v3r2
RHEL-09-631010 - RHEL 9, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
SLES-12-030530 - The SUSE operating system, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
Unix
DISA SLES 12 STIG v3r1
SLES-15-010170 - The SUSE operating system, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
Unix
DISA SLES 15 STIG v2r2
UBTU-20-010066 - The Ubuntu operating system for PKI-based authentication, must implement a local cache of revocation data in case of the inability to access revocation information via the network.
Unix
DISA STIG Ubuntu 20.04 LTS v2r1
UBTU-22-612035 - Ubuntu 22.04 LTS for PKI-based authentication, must implement a local cache of revocation data in case of the inability to access revocation information via the network.
Unix
DISA STIG Canonical Ubuntu 22.04 LTS v2r2
VCSA-80-000080 The vCenter Server must enable revocation checking for certificate-based authentication.
VMware
DISA VMware vSphere 8.0 vCenter STIG v2r1