STIGQter STIGQter: STIG Summary: PostgreSQL 9.x Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Oct 2020:

The DBMS must be configured on a platform that has a NIST certified FIPS 140-2 installation of OpenSSL.

DISA Rule

SV-214157r508027_rule

Vulnerability Number

V-214157

Group Title

SRG-APP-000179-DB-000114

Rule Version

PGS9-00-012800

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Install PostgreSQL on an operating system with FIPS-compliant cryptography enabled; or by other means ensure that FIPS 140-2-certified OpenSSL libraries are used by the DBMS.

Check Contents

If the deployment incorporates a custom build of the operating system and PostgreSQL guaranteeing the use of FIPS 140-2- compliant OpenSSL, this is not a finding.
Go to the below webpage and click "show all":
https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules/search
Note: Certificates 3130, 3016, and 2441 are the most common.
If the OS is not using a FIPS 140-2 certified implementation that is listed, this is a finding.

If FIPS encryption is not enabled, this is a finding.

Vulnerability Number

V-214157

Documentable

False

Rule Version

PGS9-00-012800

Severity Override Guidance

If the deployment incorporates a custom build of the operating system and PostgreSQL guaranteeing the use of FIPS 140-2- compliant OpenSSL, this is not a finding.
Go to the below webpage and click "show all":
https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules/search
Note: Certificates 3130, 3016, and 2441 are the most common.
If the OS is not using a FIPS 140-2 certified implementation that is listed, this is a finding.

If FIPS encryption is not enabled, this is a finding.

Check Content Reference

M

Target Key

3994

Comments