1.2.4 Ensure gpgcheck is globally activated

Information

The gpgcheck option, found in the main section of the /etc/yum.conf and individual /etc/yum/repos.d/* files determines if an RPM package's signature is checked prior to its installation.
Rationale:
It is important to ensure that an RPM's package signature is always checked prior to installation to ensure that the software is obtained from a trusted source.

Solution

Edit /etc/yum.conf and set 'gpgcheck=1' in the [main] section. Edit any failing files in /etc/yum.repos.d/* and set all instances of gpgcheck to '1'.

See Also

https://workbench.cisecurity.org/files/2485

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7(6)

Plugin: Unix

Control ID: ff627abe6c848e473a70ffd9d5dfd78ec1866dd16ca86930d2bc585a4fe0406f