Check: SRG-NET-000580-VPN-002432
Virtual Private Network (VPN) SRG:
SRG-NET-000580-VPN-002432
(in versions v3 r3 through v2 r6)
Title
The VPN Gateway must configure OCSP to ensure revoked machine certificates are prohibited from establishing an allowed session. (Cat II impact)
Discussion
Situations may arise in which the certificate issued by a Certificate Authority (CA) may need to be revoked before the lifetime of the certificate expires. For example, the certificate is known to have been compromised. When an incoming Internet Key Exchange (IKE) session is initiated for a remote client or peer whose certificate is revoked, the revocation list configured for use by the VPN server is checked to see if the certificate is valid. If the certificate is revoked, IKE will fail and an IPsec security association will not be established for the remote endpoint.
Check Content
Verify the VPN Gateway rejects machine certificates that have been revoked when using DOD PKI for authentication. If the VPN Gateway does not configure OCSP and/or CRL to reject revoked machine credentials that are prohibited from establishing an allowed session, this is a finding.
Fix Text
Configure the VPN Gateway to reject machine certificates that have been revoked when using DOD PKI for authentication.
Additional Identifiers
Rule ID: SV-264333r984335_rule
Vulnerability ID: V-264333
Group Title: SRG-NET-000580
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-004068 |
For public key-based authentication, implement a local cache of revocation data to support path discovery and validation. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |