The vCenter Server must enable revocation checking for certificate-based authentication.
An XCCDF Rule
Description
The system must establish the validity of the user-supplied identity certificate using Online Certificate Status Protocol (OCSP) and/or Certificate Revocation List (CRL) revocation checking. Satisfies: SRG-APP-000175, SRG-APP-000392, SRG-APP-000401, SRG-APP-000403
- ID
- SV-258919r934415_rule
- Version
- VCSA-80-000080
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider >> Smart Card Authentication.
Under Smart card authentication settings >> Certificate revocation, click the "Edit" button.
Configure revocation checking per site requirements. OCSP with CRL failover is recommended.