OL 9 must enable FIPS mode.
DISA Rule
SV-271454r1092458_rule
Vulnerability Number
V-271454
Group Title
SRG-OS-000033-GPOS-00014
Rule Version
OL09-00-000070
Severity
CAT I
CCI(s)
- CCI-000068 - Implement cryptographic mechanisms to protect the confidentiality of remote access sessions.
- CCI-000877 - Employ strong authentication in the establishment of nonlocal maintenance and diagnostic sessions.
- CCI-002450 - Implement organization-defined types of cryptography for each specified cryptography use.
- CCI-002418 - Protect the confidentiality and/or integrity of transmitted information.
Weight
10
Fix Recommendation
Configure OL 9 to implement FIPS mode with the following command:
$ sudo fips-mode-setup --enable
Reboot the system for the changes to take effect.
Check Contents
Verify that OL 9 is in FIPS mode with the following command:
$ fips-mode-setup --check
FIPS mode is enabled.
If FIPS mode is not enabled, this is a finding.
Vulnerability Number
V-271454
Documentable
False
Rule Version
OL09-00-000070
Severity Override Guidance
Verify that OL 9 is in FIPS mode with the following command:
$ fips-mode-setup --check
FIPS mode is enabled.
If FIPS mode is not enabled, this is a finding.
Check Content Reference
M
Target Key
5680