1.2.3 Ensure gpgcheck is globally activated

Information

It is important to ensure that an RPM's package signature is always checked prior to installation to ensure that the software is obtained from a trusted source.

Solution

Edit /etc/yum.conf and set 'gpgcheck=1' in the [main] section.Edit any failing files in /etc/yum.repos.d/* and set all instances of gpgcheck to '1'.

See Also

https://benchmarks.cisecurity.org/tools2/linux/CIS_Amazon_Linux_Benchmark_v2.0.0.pdf

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7

Plugin: Unix

Control ID: b21d4cfe39c5c48962c2154acdbd7ee2028b1f24667296ee4e16b4ecb70926dd