The EDB Postgres Advanced Server must be configured on a platform that has a NIST certified FIPS 140-2 installation of OpenSSL.
DISA Rule
SV-213668r508024_rule
Vulnerability Number
V-213668
Group Title
SRG-APP-000179-DB-000114
Rule Version
PPS9-00-013200
Severity
CAT I
CCI(s)
- CCI-000803 - The information system implements mechanisms for authentication to a cryptographic module that meet the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.
Weight
10
Fix Recommendation
Install Postgres Plus Advanced Server on RHEL or ensure that FIPS 140-2 certified OpenSSL libraries are used by the DBMS.
Check Contents
If the Postgres Plus Advanced Server is not installed on Red Hat Enterprise Linux (RHEL), this is a finding.
Vulnerability Number
V-213668
Documentable
False
Rule Version
PPS9-00-013200
Severity Override Guidance
If the Postgres Plus Advanced Server is not installed on Red Hat Enterprise Linux (RHEL), this is a finding.
Check Content Reference
M
Target Key
3988
Comments