UCF STIG Viewer Logo

Samsung Android Workspace must be configured to enable Certificate Revocation List (CRL) status checking.


Finding ID Version Rule ID IA Controls Severity
V-93913 KNOX-09-001045 SV-103999r1_rule Medium
A CRL allows a certificate issuer to revoke a certificate for any reason, including improperly issued certificates and compromise of the private keys. Checking the revocation status of the certificate mitigates the risk associated with using a compromised certificate. SFR ID: FMT_SMF_EXT.1.1 #47
Samsung Android OS 9 with Knox 3.x COPE Use Case KPE(Legacy) Deployment Security Technical Implementation Guide 2019-10-01


Check Text ( C-93231r1_chk )
Review the Samsung Android Workspace configuration settings to confirm that CRL checking is enabled for all apps.

This procedure is performed on the MDM Administration console only.

On the MDM console, for the Workspace, in the "Knox certificate" group, verify that "revocation check" is configured to "enable for all apps".

If on the MDM console "revocation check" is not configured to "enable for all apps", this is a finding.
Fix Text (F-100161r1_fix)
Configure Samsung Android Workspace to enable CRL checking for all apps.

On the MDM console, for the Workspace, in the "Knox certificate" group, configure "revocation check" to "enable for all apps".

Refer to the MDM documentation to determine how to configure revocation checking to "enable for all apps". Some may, for example, allow a wildcard string: "*" (asterisk).