The container platform, for PKI-based authentication, must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-233201SRG-APP-000401-CTR-000965SV-233201r981893_ruleCCI-004068medium
Description
The potential of allowing access to users who are no longer authorized (have revoked certificates) increases unless a local cache of revocation data is configured.
STIGDate
Container Platform Security Requirements Guide2025-05-15

Details

Check Text (C-233201r981893_chk)

Review the container platform configuration. If the container platform is not implemented to use a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, this is a finding.

Fix Text (F-36105r601091_fix)

Configure the container platform to implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.