The Photon operating system must have the OpenSSL FIPS provider installed to protect the confidentiality of remote access sessions.
DISA Rule
SV-258806r958408_rule
Vulnerability Number
V-258806
Group Title
SRG-OS-000033-GPOS-00014
Rule Version
PHTN-40-000013
Severity
CAT I
CCI(s)
- CCI-000068 - Implement cryptographic mechanisms to protect the confidentiality of remote access sessions.
- CCI-002418 - Protect the confidentiality and/or integrity of transmitted information.
- CCI-002420 - Maintain the confidentiality and/or integrity of information during preparation for transmission.
- CCI-002422 - Maintain the confidentiality and/or integrity of information during reception.
- CCI-002890 - Implement organization-defined cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications.
- CCI-003123 - Implement organization-defined cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.
Weight
10
Fix Recommendation
At the command line, run the following command:
# tdnf install openssl-fips-provider
Check Contents
At the command line, run the following command to verify the OpenSSL FIPS provider is installed:
# rpm -qa | grep openssl-fips
Example result:
openssl-fips-provider-3.0.3-1.ph4.x86_64
If there is no output indicating that the OpenSSL FIPS provider is installed, this is a finding.
Vulnerability Number
V-258806
Documentable
False
Rule Version
PHTN-40-000013
Severity Override Guidance
At the command line, run the following command to verify the OpenSSL FIPS provider is installed:
# rpm -qa | grep openssl-fips
Example result:
openssl-fips-provider-3.0.3-1.ph4.x86_64
If there is no output indicating that the OpenSSL FIPS provider is installed, this is a finding.
Check Content Reference
M
Target Key
5569