The container platform, for PKI-based authentication, must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-233201SRG-APP-000401-CTR-000965SV-233201r981893_ruleCCI-004068medium
Description
The potential of allowing access to users who are no longer authorized (have revoked certificates) increases unless a local cache of revocation data is configured.
STIGDate
Container Platform Security Requirements Guide2025-05-15

Related Frameworks

2 paths across 2 frameworks
NIST 800-531 mapping
  • DISA · 2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-004068
1.00
  • DISA · 2 · disa_xccdf · related

Details

Check Text (C-233201r981893_chk)

Review the container platform configuration. If the container platform is not implemented to use a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, this is a finding.

Fix Text (F-36105r601091_fix)

Configure the container platform to implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.