STIGQter STIGQter: STIG Summary: Oracle Linux 8 Security Technical Implementation Guide Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

OL 8 must implement NIST FIPS-validated cryptography for the following: To provision digital signatures, to generate cryptographic hashes, and to protect data requiring data-at-rest protections in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.

DISA Rule

SV-248524r1069154_rule

Vulnerability Number

V-248524

Group Title

SRG-OS-000033-GPOS-00014

Rule Version

OL08-00-010020

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the operating system to implement DOD-approved encryption by following the steps below:

To enable strict FIPS compliance, the fips=1 kernel option must be added to the kernel boot parameters during system installation so key generation is done with FIPS-approved algorithms and continuous monitoring tests in place.

Enable FIPS mode after installation (not strict FIPS-compliant) with the following command:

$ sudo fips-mode-setup --enable

Reboot the system for the changes to take effect.

Check Contents

Verify the operating system implements DOD-approved encryption to protect the confidentiality of remote access sessions.

Check to see if FIPS mode is enabled with the following command:

$ fips-mode-setup --check
FIPS mode is enabled

If FIPS mode is "enabled", check if the kernel boot parameter is configured for FIPS mode with the following command:

$ sudo grub2-editenv list | grep fips
kernelopts=...fips=1

If the kernel boot parameter is configured to use FIPS mode, check to see if the system is in FIPS mode with the following command:

$ sudo cat /proc/sys/crypto/fips_enabled
1

If FIPS mode is not "enabled", the kernel boot parameter is not configured for FIPS mode, or the system does not have a value of "1" for "fips_enabled" in "/proc/sys/crypto", this is a finding.

Vulnerability Number

V-248524

Documentable

False

Rule Version

OL08-00-010020

Severity Override Guidance

Verify the operating system implements DOD-approved encryption to protect the confidentiality of remote access sessions.

Check to see if FIPS mode is enabled with the following command:

$ fips-mode-setup --check
FIPS mode is enabled

If FIPS mode is "enabled", check if the kernel boot parameter is configured for FIPS mode with the following command:

$ sudo grub2-editenv list | grep fips
kernelopts=...fips=1

If the kernel boot parameter is configured to use FIPS mode, check to see if the system is in FIPS mode with the following command:

$ sudo cat /proc/sys/crypto/fips_enabled
1

If FIPS mode is not "enabled", the kernel boot parameter is not configured for FIPS mode, or the system does not have a value of "1" for "fips_enabled" in "/proc/sys/crypto", this is a finding.

Check Content Reference

M

Target Key

5416