Skip to content

The vCenter Server must enable revocation checking for certificate-based authentication.

An XCCDF Rule

Description

The system must establish the validity of the user-supplied identity certificate using Online Certificate Status Protocol (OCSP) and/or Certificate Revocation List (CRL) revocation checking. Satisfies: SRG-APP-000175, SRG-APP-000392, SRG-APP-000401, SRG-APP-000403

ID
SV-258919r934415_rule
Version
VCSA-80-000080
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider >> Smart Card Authentication.

Under Smart card authentication settings >> Certificate revocation, click the "Edit" button.

Configure revocation checking per site requirements. OCSP with CRL failover is recommended.