OL6-00-000008 - Vendor-provided cryptographic certificates must be installed to verify the integrity of system software.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This key is necessary to cryptographically verify packages that packages are from the operating system vendor.

Solution

To ensure the system can cryptographically verify the software packages come from the operating system vendor (and connect to the vendor's network software repository to receive them if desired), the vendor GPG key must properly be installed. To ensure the GPG key is installed, run:

# wget http://public-yum.oracle.com/RPM-GPG-KEY-oracle-ol6
# rpm --import RPM-GPG-KEY-oracle-ol6

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_6_V1R17_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7(6), CAT|I, CCI|CCI-000352, CSCv6|2.2, Group-ID|V-50689, Rule-ID|SV-64895r3_rule, STIG-ID|OL6-00-000008, Vuln-ID|V-50689

Plugin: Unix

Control ID: d5315cf5f70089c10a792d8494faabab69463b213733c6a8c95a6e88712c25e7