SV-261929r1193220_rule
V-261929
SRG-APP-000427-DB-000385
CD16-00-008400
CAT II
10
Revoke trust in any certificates not issued by a DOD-approved certificate authority.
Configure PostgreSQL to accept only DOD and DOD-approved PKI end-entity certificates.
To configure PostgreSQL to accept approved CAs, refer to the official PostgreSQL documentation: http://www.postgresql.org/docs/current/static/ssl-tcp.html
For more information on configuring PostgreSQL to use SSL, refer to supplementary content APPENDIX-G.
As the database administrator (shown here as "postgres"), verify the following setting in postgresql.conf:
$ sudo su - postgres
$ psql -c "SHOW ssl_ca_file"
$ psql -c "SHOW ssl_cert_file"
If the database is not configured to use only DOD-approved certificates, this is a finding.
V-261929
False
CD16-00-008400
As the database administrator (shown here as "postgres"), verify the following setting in postgresql.conf:
$ sudo su - postgres
$ psql -c "SHOW ssl_ca_file"
$ psql -c "SHOW ssl_cert_file"
If the database is not configured to use only DOD-approved certificates, this is a finding.
M
5598