STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 31 Oct 2023:

The Photon operating system must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.

DISA Rule

SV-258852r933617_rule

Vulnerability Number

V-258852

Group Title

SRG-OS-000478-GPOS-00223

Rule Version

PHTN-40-000182

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Navigate to and open:

/boot/grub2/grub.cfg

Locate the boot command line arguments. An example follows:

linux /boot/$photon_linux root=$rootpartition $photon_cmdline $systemd_cmdline

Add "fips=1" to the end of the line so it reads as follows:

linux /boot/$photon_linux root=$rootpartition $photon_cmdline $systemd_cmdline fips=1

Note: Do not copy/paste in this example argument line. This may change in future releases. Find the similar line and append "fips=1" to it.

Reboot the system for the change to take effect.

Check Contents

At the command line, run the following command to verify FIPS is enabled for the OS:

# cat /proc/sys/crypto/fips_enabled

Example result:

1

If "fips_enabled" is not set to "1", this is a finding.

Vulnerability Number

V-258852

Documentable

False

Rule Version

PHTN-40-000182

Severity Override Guidance

At the command line, run the following command to verify FIPS is enabled for the OS:

# cat /proc/sys/crypto/fips_enabled

Example result:

1

If "fips_enabled" is not set to "1", this is a finding.

Check Content Reference

M

Target Key

5569