1.6.1 TLS Check Key Usage

Information

This sequence describes configuring TLS to enforce key usage checking

The Extended Key Usage X.509 v3 extension defines one or more purposes for which the public key can be used. This is in addition to or in place of the basic purposes specified by the Key Usage extension. As per NDcPP recommendation, that a peer certificate being used to establish TLS connection must have its extended key usage field set as client-auth or server-auth, depending on its role of the peer device. This configuration enables the checking of key usage during TLS handshake. It is disabled by default.

Solution

switch# conf
switch(config)# tls check-key-usage

See Also

https://workbench.cisecurity.org/benchmarks/24202

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), 800-53|SC-28, 800-53|SC-28(1), CSCv7|14.4, CSCv7|14.8

Plugin: ArubaOS

Control ID: 045abeeed686236c4977fb1e34b3c58096c7f3b1ee7ec84562240c790d9f5eee