1.2.2 Verify Red Hat GPG Key is Installed

Information

Configuration Level : Level-I

Solution

Compare the GPG fingerprint with the one from Red Hat's web site at http-//www.redhat.com/security/team/key. The following command can be used to print the installed release key's fingerprint, which is actually contained in the file referenced below-# gpg --quiet --with-fingerprint /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-releaseMore information on package signing is also available at https-//access.redhat.com/security/team/key.

See Also

https://workbench.cisecurity.org/files/214

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7(6), CCE|CCE-14440-2

Plugin: Unix

Control ID: 9ee5ae8f817a34807fc9b416f6eefe678fe15e934f984561fa093f1cd8a47531