RHEL-09-672015 - RHEL 9 crypto policy files must match files shipped with the operating system.

Information

The RHEL 9 package 'crypto-policies' defines the cryptography policies for the system.

If the files are changed from those shipped with the operating system, it may be possible for RHEL 9 to use cryptographic functions that are not FIPS 140-3 approved.

Satisfies: SRG-OS-000478-GPOS-00223, SRG-OS-000396-GPOS-00176

Solution

Reinstall the crypto-policies package to remove any modifications.

$ sudo dnf reinstall crypto-policies

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_9_V2R1_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|I, CCI|CCI-002450, Rule-ID|SV-258235r959006_rule, STIG-ID|RHEL-09-672015, Vuln-ID|V-258235

Plugin: Unix

Control ID: 19d12ba9f936b5fd47ce5396c89c03dac2f30975859075b99f17ff887cd947c3