STIGQter STIGQter: STIG Summary: Redis Enterprise 6.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

Redis Enterprise DBMS must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to protect unclassified information requiring confidentiality and cryptographic protection, in accordance with the data owners requirements.

DISA Rule

SV-251234r961857_rule

Vulnerability Number

V-251234

Group Title

SRG-APP-000514-DB-000383

Rule Version

RD6X-00-010000

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To configure the operating system to implement DoD-approved encryption, review the official RHEL Documentation: https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/security_guide/chap-federal_standards_and_regulations

Check Contents

Verify the operating system implements FIPS compliant cryptographic modules.

As the system administrator, run the following to determine if FIPS is enabled:
# cat /proc/sys/crypto/fips_enabled

If fips_enabled is not 1, this is a finding.

Vulnerability Number

V-251234

Documentable

False

Rule Version

RD6X-00-010000

Severity Override Guidance

Verify the operating system implements FIPS compliant cryptographic modules.

As the system administrator, run the following to determine if FIPS is enabled:
# cat /proc/sys/crypto/fips_enabled

If fips_enabled is not 1, this is a finding.

Check Content Reference

M

Target Key

5443