STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288259

CAT II (Medium)

The application, for PKI-based authentication, must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.

Rule ID

SV-288259r1252954_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-004068

Discussion

Without configuring a local cache of revocation data, there is the potential to allow access to users who are no longer authorized (users with revoked certificates). Online certificate status protocol (OCSP) is preferred over certificate revocation lists (CRLs). If OCSP is used, this requirement is not applicable.

Check Content

CRL must only be used as a fallback if an OSCP function is not available.

Review the application documentation and deployed configuration to determine whether the application, for PKI-based authentication, implements a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.

If the application does not, for PKI-based authentication, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, this is a finding.

Fix Text

For PKI-based authentication without OSCP, configure the application to implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.