The Photon operating system RPM package management tool must cryptographically verify the authenticity of all software packages during installation.
DISA Rule
SV-239134r675210_rule
Vulnerability Number
V-239134
Group Title
SRG-OS-000366-GPOS-00153
Rule Version
PHTN-67-000063
Severity
CAT II
CCI(s)
- CCI-001749 - The information system prevents the installation of organization-defined software components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
Weight
10
Fix Recommendation
Open /etc/tdnf/tdnf.conf with a text editor.
Remove any existing gpgcheck setting and add the following line:
gpgcheck=1
Check Contents
At the command line, execute the following command:
# grep "^gpgcheck" /etc/tdnf/tdnf.conf
If "gpgcheck" is not set to "1", this is a finding.
Vulnerability Number
V-239134
Documentable
False
Rule Version
PHTN-67-000063
Severity Override Guidance
At the command line, execute the following command:
# grep "^gpgcheck" /etc/tdnf/tdnf.conf
If "gpgcheck" is not set to "1", this is a finding.
Check Content Reference
M
Target Key
5323
Comments