STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 9 Security Technical Implementation Guide Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

RHEL 9 must have the AIDE package installed.

DISA Rule

SV-258134r1155620_rule

Vulnerability Number

V-258134

Group Title

SRG-OS-000363-GPOS-00150

Rule Version

RHEL-09-651010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Install AIDE, initialize it, and perform a manual check.

Install AIDE:

$ sudo dnf install aide

Initialize AIDE:

$ sudo /usr/sbin/aide --init

Example output:

Start timestamp: 2023-06-05 10:09:04 -0600 (AIDE 0.16)
AIDE initialized database at /var/lib/aide/aide.db.new.gz

Number of entries: 86833

---------------------------------------------------
The attributes of the (uncompressed) database(s):
---------------------------------------------------

/var/lib/aide/aide.db.new.gz
MD5 : coZUtPHhoFoeD7+k54fUvQ==
SHA1 : DVpOEMWJwo0uPgrKZAygIUgSxeM=
SHA256 : EQiZH0XNEk001tcDmJa+5STFEjDb4MPE
TGdBJ/uvZKc=
SHA512 : 86KUqw++PZhoPK0SZvT3zuFq9yu9nnPP
toei0nENVELJ1LPurjoMlRig6q69VR8l
+44EwO9eYyy9nnbzQsfG1g==

End timestamp: 2023-06-05 10:09:57 -0600 (run time: 0m 53s)

The new database will need to be renamed to be read by AIDE:

$ sudo mv /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz

Perform a manual check:

$ sudo /usr/sbin/aide --check

Example output:

2023-06-05 10:16:08 -0600 (AIDE 0.16)
AIDE found NO differences between database and filesystem. Looks okay!!

...

Check Contents

Verify the file integrity tool is configured to verify ACLs.

Note: AIDE is highly configurable at install time. This requirement assumes the "aide.conf" file is under the "/etc" directory.

Verify AIDE is installed with the following command:

$ sudo dnf list installed aide

Updating Subscription Management repositories.
Installed Packages
aide.x86_64 0.16-103.el9 @rhel-9-for-x86_64-appstream-rpms

Use the following command to determine if the file is in a location other than "/etc/aide/aide.conf":

$ sudo find / -name aide.conf

If AIDE is not installed, ask the system administrator (SA) how file integrity checks are performed on the system.

Vulnerability Number

V-258134

Documentable

False

Rule Version

RHEL-09-651010

Severity Override Guidance

Verify the file integrity tool is configured to verify ACLs.

Note: AIDE is highly configurable at install time. This requirement assumes the "aide.conf" file is under the "/etc" directory.

Verify AIDE is installed with the following command:

$ sudo dnf list installed aide

Updating Subscription Management repositories.
Installed Packages
aide.x86_64 0.16-103.el9 @rhel-9-for-x86_64-appstream-rpms

Use the following command to determine if the file is in a location other than "/etc/aide/aide.conf":

$ sudo find / -name aide.conf

If AIDE is not installed, ask the system administrator (SA) how file integrity checks are performed on the system.

Check Content Reference

M

Target Key

5551