RHEL-09-672015 - RHEL 9 crypto policy files must match files shipped with the operating system.

Information

The RHEL 9 package 'crypto-policies' defines the cryptography policies for the system.

If the files are changed from those shipped with the operating system, it may be possible for RHEL 9 to use cryptographic functions that are not FIPS 140-3 approved.

Satisfies: SRG-OS-000478-GPOS-00223, SRG-OS-000396-GPOS-00176

Solution

Reinstall the crypto-policies package to remove any modifications.

$ sudo dnf reinstall crypto-policies

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/U_RHEL_9_V1R1_STIG.zip

Item Details

References: CAT|I, CCI|CCI-002450, Rule-ID|SV-258235r926692_rule, STIG-ID|RHEL-09-672015, Vuln-ID|V-258235

Plugin: Unix

Control ID: acc96cd5a8f3ab6fd96ff7ff9c5590521d0aba03f2dcdb18942b392e2dc1b3ab