STIGQter STIGQter: STIG Summary: VMware vRealize Automation 7.x SLES Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

The RPM package management tool must cryptographically verify the authenticity of all software packages during installation.

DISA Rule

SV-100451r1_rule

Vulnerability Number

V-89801

Group Title

SRG-OS-000366-GPOS-00153

Rule Version

VRAU-SL-001170

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Edit the RPM configuration files containing the "nosignature" option and remove the option.

Check Contents

Verify RPM signature validation is not disabled:

# grep nosignature /usr/lib/rpm/rpmrc ~root/.rpmrc

The result should either respond with no such file or directory, or an empty return.

If any configuration is found, this is a finding.

Vulnerability Number

V-89801

Documentable

False

Rule Version

VRAU-SL-001170

Severity Override Guidance

Verify RPM signature validation is not disabled:

# grep nosignature /usr/lib/rpm/rpmrc ~root/.rpmrc

The result should either respond with no such file or directory, or an empty return.

If any configuration is found, this is a finding.

Check Content Reference

M

Target Key

3459

Comments