Check: SRG-NET-000512-VPN-002230
Virtual Private Network (VPN) SRG:
SRG-NET-000512-VPN-002230
(in versions v2 r5 through v1 r0.1)
Title
The VPN Gateway must not accept certificates that have been revoked when using PKI for authentication. (Cat I impact)
Discussion
Situations may arise in which the certificate issued by a Certificate Authority (CA) may need to be revoked before the lifetime of the certificate expires. For example, the certificate is known to have been compromised. When an incoming Internet Key Exchange (IKE) session is initiated for a remote client or peer whose certificate is revoked, the revocation list configured for use by the VPN server is checked to see if the certificate is valid; if the certificate is revoked, IKE will fail and an IPsec security association will not be established for the remote endpoint.
Check Content
Verify the VPN Gateway does not accept certificates that have been revoked when using PKI for authentication. If the VPN Gateway accepts certificates that have been revoked when using PKI for authentication, this is a finding.
Fix Text
Configure the VPN Gateway to not accept certificates that have been revoked when using PKI for authentication.
Additional Identifiers
Rule ID: SV-207253r608988_rule
Vulnerability ID: V-207253
Group Title: SRG-NET-000512
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |