UCF STIG Viewer Logo

Samsung Android must be configured to enable Certificate Revocation List (CRL) status checking.


Overview

Finding ID Version Rule ID IA Controls Severity
V-93817 KNOX-09-001050 SV-103903r1_rule Medium
Description
A CRL allows a certificate issuer to revoke a certificate for any reason, including improperly issued certificates and compromise of the private keys. Checking the revocation status of the certificate mitigates the risk associated with using a compromised certificate. SFR ID: FMT_SMF_EXT.1.1 #47
STIG Date
Samsung Android OS 9 with Knox 3.x COPE Use Case KPE(AE) Deployment Security Technical Implementation Guide 2020-02-24

Details

Check Text ( C-93135r1_chk )
Review device configuration settings to confirm that CRL checking is enabled for all apps.

This procedure is performed on the MDM Administration console only.

On the MDM console, for the device, in the "Knox certificate" group, verify that "revocation check" is configured to "enable for all apps".

If on the MDM console "revocation check" is not configured to "enable for all apps", this is a finding.
Fix Text (F-100063r1_fix)
Configure Samsung Android to enable CRL checking for all apps.

On the MDM console, for the device, in the "Knox certificate" group, configure "revocation check" to "enable for all apps".

Refer to the MDM documentation to determine how to configure revocation checking to "enable for all apps". Some may, for example, allow a wildcard string: "*" (asterisk).