Rule ID
SV-288260r1252975_rule
Version
V1R0.1
CCIs
Public key cryptography is a valid authentication mechanism for individuals, machines, and devices. For Public Key Infrastructure (PKI) solutions, status information for certification paths includes certificate revocation lists or certificate status protocol responses. For personal identity verification (PIV) cards, certificate validation involves the construction and verification of a certification path to the Common Policy Root trust anchor, which includes certificate policy processing. Implementing a local cache of revocation data to support path discovery and validation also supports system availability in situations where organizations are unable to access revocation information via the network. Online certificate status protocol (OCSP) is preferred over certificate revocation lists (CRLs). If OCSP is used this requirement is not applicable.
CRL must only be used as a fallback if an OSCP function is not available. Review the application documentation and deployed configuration to determine whether the application, for public key-based authentication, implements a local cache of revocation data to support path discovery and validation. If the application does not, for public key-based authentication, implement a local cache of revocation data to support path discovery and validation, this is a finding.
For public key-based authentication without OSCP, configure the application to implement a local cache of revocation data to support path discovery and validation.