The Photon operating system RPM package management tool must cryptographically verify the authenticity of all software packages during installation.
DISA Rule
SV-239133r675207_rule
Vulnerability Number
V-239133
Group Title
SRG-OS-000366-GPOS-00153
Rule Version
PHTN-67-000062
Severity
CAT II
CCI(s)
- CCI-001749 - The information system prevents the installation of organization-defined software components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
Weight
10
Fix Recommendation
Open the file containing "nosignature" with a text editor and remove the option.
Check Contents
At the command line, execute the following command:
# grep -s nosignature /usr/lib/rpm/rpmrc /etc/rpmrc ~root/.rpmrc
If the command returns any output, this is a finding.
Vulnerability Number
V-239133
Documentable
False
Rule Version
PHTN-67-000062
Severity Override Guidance
At the command line, execute the following command:
# grep -s nosignature /usr/lib/rpm/rpmrc /etc/rpmrc ~root/.rpmrc
If the command returns any output, this is a finding.
Check Content Reference
M
Target Key
5323
Comments