STIGQter STIGQter: STIG Summary: VMware vRealize Operations Manager 6.x SLES Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

The RPM package management tool must cryptographically verify the authenticity of all software packages during installation.

DISA Rule

SV-99335r1_rule

Vulnerability Number

V-88685

Group Title

SRG-OS-000366-GPOS-00153

Rule Version

VROM-SL-001145

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Edit the RPM configuration files containing the "nosignature" option and remove the option.

Check Contents

Verify RPM signature validation is not disabled:

# grep nosignature /usr/lib/rpm/rpmrc ~root/.rpmrc

The result should either respond with no such file or directory, or an empty return.

If any configuration is found, this is a finding.

Vulnerability Number

V-88685

Documentable

False

Rule Version

VROM-SL-001145

Severity Override Guidance

Verify RPM signature validation is not disabled:

# grep nosignature /usr/lib/rpm/rpmrc ~root/.rpmrc

The result should either respond with no such file or directory, or an empty return.

If any configuration is found, this is a finding.

Check Content Reference

M

Target Key

3461

Comments