GEN005306 - The SNMP service must require the use of a FIPS 140-2 approved cryptographic hash algorithm as part of its authentication and integrity methods.

Information

The SNMP service must use SHA-1 or a FIPS 140-2 approved successor for authentication and integrity.

Solution

Edit /etc/snmp/snmpd.conf and add the SHA keyword for any create user statement without one.

Restart the SNMP service.
# service snmpd restart

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V1R14_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-001453, Rule-ID|SV-63407r1_rule, STIG-ID|GEN005306, Vuln-ID|V-22448

Plugin: Unix

Control ID: 099d75e9e203bd75bda0ed3da16dffae32a926dea4aa84d10b843901c7c5f637