SV-252930r1016301_rule
V-252930
SRG-OS-000366-GPOS-00153
TOSS-04-010220
CAT I
10
Configure TOSS to prevent the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization by setting the following option in the "/etc/yum.repos.d/[your_repo_name].repo" file(s):
gpgcheck=1
Verify TOSS prevents the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
Check that YUM verifies the signature of packages from a repository prior to install with the following command:
$ sudo egrep '^\[.*\]|gpgcheck' /etc/yum.repos.d/*.repo
/etc/yum.repos.d/appstream.repo:[appstream]
/etc/yum.repos.d/appstream.repo:gpgcheck=1
/etc/yum.repos.d/baseos.repo:[baseos]
/etc/yum.repos.d/baseos.repo:gpgcheck=1
If "gpgcheck" is not set to "1", or if options are missing or commented out, ask the System Administrator how the certificates for patches and other operating system components are verified.
If there is no process to validate certificates that is approved by the organization, this is a finding.
V-252930
False
TOSS-04-010220
Verify TOSS prevents the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
Check that YUM verifies the signature of packages from a repository prior to install with the following command:
$ sudo egrep '^\[.*\]|gpgcheck' /etc/yum.repos.d/*.repo
/etc/yum.repos.d/appstream.repo:[appstream]
/etc/yum.repos.d/appstream.repo:gpgcheck=1
/etc/yum.repos.d/baseos.repo:[baseos]
/etc/yum.repos.d/baseos.repo:gpgcheck=1
If "gpgcheck" is not set to "1", or if options are missing or commented out, ask the System Administrator how the certificates for patches and other operating system components are verified.
If there is no process to validate certificates that is approved by the organization, this is a finding.
M
5469