STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 9 Security Technical Implementation Guide Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

RHEL 9 must not have the gssproxy package installed.

DISA Rule

SV-257832r1155653_rule

Vulnerability Number

V-257832

Group Title

SRG-OS-000095-GPOS-00049

Rule Version

RHEL-09-215045

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove the gssproxy package with the following command:

$ sudo dnf remove gssproxy

Check Contents

Note: If NFS mounts are authorized and in use on the system, this control is not applicable.

Verify the gssproxy package is not installed with the following command:

$ dnf list --installed gssproxy

Error: No matching Packages to list

If the "gssproxy" package is installed and is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.

Vulnerability Number

V-257832

Documentable

False

Rule Version

RHEL-09-215045

Severity Override Guidance

Note: If NFS mounts are authorized and in use on the system, this control is not applicable.

Verify the gssproxy package is not installed with the following command:

$ dnf list --installed gssproxy

Error: No matching Packages to list

If the "gssproxy" package is installed and is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.

Check Content Reference

M

Target Key

5551