SV-253055r991589_rule
V-253055
SRG-OS-000480-GPOS-00227
TOSS-04-031380
CAT II
10
Configure the operating system to encrypt offloaded audit logs by installing the required packages with the following command:
$ sudo yum install rsyslog-gnutls
Verify the operating system has the packages required for encrypting offloaded audit logs installed with the following commands:
$ sudo yum list installed rsyslog-gnutls
rsyslog-gnutls.x86_64 8.2102.0-5.el8 @AppStream
If the "rsyslog-gnutls" package is not installed, ask the administrator to indicate how audit logs are being encrypted during offloading and what packages are installed to support it. If there is no evidence of audit logs being encrypted during offloading, this is a finding.
V-253055
False
TOSS-04-031380
Verify the operating system has the packages required for encrypting offloaded audit logs installed with the following commands:
$ sudo yum list installed rsyslog-gnutls
rsyslog-gnutls.x86_64 8.2102.0-5.el8 @AppStream
If the "rsyslog-gnutls" package is not installed, ask the administrator to indicate how audit logs are being encrypted during offloading and what packages are installed to support it. If there is no evidence of audit logs being encrypted during offloading, this is a finding.
M
5469