Check: KNOX-09-001050
Samsung OS 9 with Knox 3.x COBO Use Case KPE(AE) Deployment STIG:
KNOX-09-001050
(in versions v1 r4 through v1 r1)
Title
Samsung Android must be configured to enable Certificate Revocation List (CRL) status checking. (Cat II impact)
Discussion
A CRL allows a certificate issuer to revoke a certificate for any reason, including improperly issued certificates and compromise of the private keys. Checking the revocation status of the certificate mitigates the risk associated with using a compromised certificate. SFR ID: FMT_SMF_EXT.1.1 #47
Check Content
Review device configuration settings to confirm that CRL checking is enabled for all apps. This procedure is performed on the MDM Administration console only. On the MDM console, for the device, in the "Knox certificate" group, verify that "revocation check" is configured to "enable for all apps". If on the MDM console "revocation check" is not configured to "enable for all apps", this is a finding.
Fix Text
Configure Samsung Android to enable CRL checking for all apps. On the MDM console, for the device, in the "Knox certificate" group, configure "revocation check" to "enable for all apps". Refer to the MDM documentation to determine how to configure revocation checking to "enable for all apps". Some may, for example, allow a wildcard string: "*" (asterisk).
Additional Identifiers
Rule ID: SV-217690r388482_rule
Vulnerability ID: V-217690
Group Title: PP-MDF-991000
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |