The macOS system must set smart card certificate trust to moderateID: oval:org.secpod.oval:def:99410 | Date: (C)2024-04-22 (M)2024-04-23 |
Class: COMPLIANCE | Family: macos |
The macOS system must be configured to block access to users who are no longer authorized (i.e., users with revoked certificates). To prevent the use of untrusted certificates, the certificates on a smart card must meet the following criteria: its issuer has a system-trusted certificate, the certificate is not expired, its valid-after date is in the past, and it passes Certificate Revocation List (CRL) and Online Certificate Status Protocol (OCSP) checking.