Rule ID
SV-288259r1252954_rule
Version
V1R0.1
CCIs
Without configuring a local cache of revocation data, there is the potential to allow access to users who are no longer authorized (users with revoked certificates). Online certificate status protocol (OCSP) is preferred over certificate revocation lists (CRLs). If OCSP is used, this requirement is not applicable.
CRL must only be used as a fallback if an OSCP function is not available. Review the application documentation and deployed configuration to determine whether the application, for PKI-based authentication, implements a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network. If the application does not, for PKI-based authentication, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, this is a finding.
For PKI-based authentication without OSCP, configure the application to implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.