STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 9 Security Technical Implementation Guide Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

RHEL 9 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure.

DISA Rule

SV-258174r958424_rule

Vulnerability Number

V-258174

Group Title

SRG-OS-000046-GPOS-00022

Rule Version

RHEL-09-653125

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Edit the aliases map file (by default /etc/aliases) used by Postfix and configure a root alias (using the user ISSO as an example):

root: ISSO

and then update the aliases database with the command:

$ sudo newaliases

Check Contents

Verify that RHEL 9 is configured to notify the appropriate interactive users in the event of an audit processing failure.

Find the alias maps that are being used with the following command:

$ postconf alias_maps

alias_maps = hash:/etc/aliases

Query the Postfix alias maps for an alias for the root user with the following command:

$ postmap -q root hash:/etc/aliases
isso

If an alias is not set, this is a finding.

Vulnerability Number

V-258174

Documentable

False

Rule Version

RHEL-09-653125

Severity Override Guidance

Verify that RHEL 9 is configured to notify the appropriate interactive users in the event of an audit processing failure.

Find the alias maps that are being used with the following command:

$ postconf alias_maps

alias_maps = hash:/etc/aliases

Query the Postfix alias maps for an alias for the root user with the following command:

$ postmap -q root hash:/etc/aliases
isso

If an alias is not set, this is a finding.

Check Content Reference

M

Target Key

5551