SV-259167r935405_rule
V-259167
SRG-APP-000089-DB-000064
VCPG-80-000005
CAT II
10
A script is included with vCenter to generate a PostgreSQL STIG configuration.
At the command prompt, run the following commands:
# chmod +x /opt/vmware/vpostgres/current/bin/vmw_vpg_config/vmw_vpg_config.py
# /opt/vmware/vpostgres/current/bin/vmw_vpg_config/vmw_vpg_config.py --action stig_enable --pg-data-dir /storage/db/vpostgres
# chmod -x /opt/vmware/vpostgres/current/bin/vmw_vpg_config/vmw_vpg_config.py
Restart the PostgreSQL service by running the following command:
# vmon-cli --restart vmware-vpostgres
At the command prompt, run the following command:
# /opt/vmware/vpostgres/current/bin/psql -U postgres -A -t -c "SHOW shared_preload_libraries;"
Example result:
health_status_worker,pg_stat_statements,pgaudit
If the output from the command does not include pgaudit, this is a finding.
V-259167
False
VCPG-80-000005
At the command prompt, run the following command:
# /opt/vmware/vpostgres/current/bin/psql -U postgres -A -t -c "SHOW shared_preload_libraries;"
Example result:
health_status_worker,pg_stat_statements,pgaudit
If the output from the command does not include pgaudit, this is a finding.
M
5570