SV-214137r508027_rule
V-214137
SRG-APP-000427-DB-000385
PGS9-00-010300
CAT II
10
Revoke trust in any certificates not issued by a DoD-approved certificate authority.
Configure PostgreSQL to accept only DoD and DoD-approved PKI end-entity certificates.
To configure PostgreSQL to accept approved CA's, see the official PostgreSQL documentation: http://www.postgresql.org/docs/current/static/ssl-tcp.html
For more information on configuring PostgreSQL to use SSL, see supplementary content APPENDIX-G.
As the database administrator (shown here as "postgres"), verify the following setting in postgresql.conf:
$ sudo su - postgres
$ psql -c "SHOW ssl_ca_file"
$ psql -c "SHOW ssl_cert_file"
If the database is not configured to used approved certificates, this is a finding.
V-214137
False
PGS9-00-010300
As the database administrator (shown here as "postgres"), verify the following setting in postgresql.conf:
$ sudo su - postgres
$ psql -c "SHOW ssl_ca_file"
$ psql -c "SHOW ssl_cert_file"
If the database is not configured to used approved certificates, this is a finding.
M
3994