ALMA-09-039290 - AlmaLinux OS 9 must use mechanisms meeting the requirements of applicable federal laws, executive orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module.

Information

The key derivation function (KDF) in Kerberos is not FIPS compatible.

Overriding the system crypto policy makes the behavior of Kerberos violate expectations, and makes system configuration more fragmented.

Solution

Configure Kerberos to use systemwide crypto policy.

Create a symlink pointing to system crypto policy in the Kerberos configuration using the following command:

$ ln -s /etc/crypto-policies/back-ends/krb5.config /usr/share/crypto-policies/FIPS/krb5.txt

See Also

https://workbench.cisecurity.org/benchmarks/0

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-7, CAT|II, CCI|CCI-000803, Rule-ID|SV-269413r1050296_rule, STIG-ID|ALMA-09-039290, Vuln-ID|V-269413

Plugin: Unix

Control ID: 293048d0d66efbf6f3cff3c69464f1d4a597ea120593603d562cfffbea55af2e