2.1620 - The system must use a file integrity tool that is configured to use FIPS 140-2 approved cryptographic hashes for validating file contents and directories - installed

Information

File integrity tools use cryptographic hashes for verifying file contents and directories have not been altered. These hashes must be FIPS 140-2 approved cryptographic hashes.

Solution

Configure the file integrity tool to use FIPS 140-2 cryptographic hashes for validating file and directory contents.

If AIDE is installed, ensure the 'sha512' rule is present on all uncommented file and directory selection lists.

See Also

https://docs.fedoraproject.org/f28/system-administrators-guide/index.html

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5), CAT|II, CCI|CCI-000366, CSCv6|2.2

Plugin: Unix

Control ID: ded17b71b89a9c2344488124c3e35d7a4998525287ff29031e8400deb70bb3b5