SV-230255r627750_rule
V-230255
SRG-OS-000250-GPOS-00093
RHEL-08-010294
CAT II
10
Configure the RHEL 8 OpenSSL library to use only DoD-approved TLS encryption by editing the following line in the "/etc/crypto-policies/back-ends/opensslcnf.config" file:
MinProtocol = TLSv1.2
A reboot is required for the changes to take effect.
Verify the OpenSSL library is configured to use only DoD-approved TLS encryption:
$ sudo grep -i MinProtocol /etc/crypto-policies/back-ends/opensslcnf.config
MinProtocol = TLSv1.2
If the "MinProtocol" is set to anything older than "TLSv1.2", this is a finding.
V-230255
False
RHEL-08-010294
Verify the OpenSSL library is configured to use only DoD-approved TLS encryption:
$ sudo grep -i MinProtocol /etc/crypto-policies/back-ends/opensslcnf.config
MinProtocol = TLSv1.2
If the "MinProtocol" is set to anything older than "TLSv1.2", this is a finding.
M
2921