RHEL 10 must enable FIPS mode.
DISA Rule
SV-281009r1184724_rule
Vulnerability Number
V-281009
Group Title
SRG-OS-000033-GPOS-00014
Rule Version
RHEL-10-000500
Severity
CAT I
CCI(s)
- CCI-000068 - Implement cryptographic mechanisms to protect the confidentiality of remote access sessions.
- CCI-000877 - Employ strong authentication in the establishment of nonlocal maintenance and diagnostic sessions.
- CCI-001453 - Implement cryptographic mechanisms to protect the integrity of remote access sessions.
- CCI-002890 - Implement organization-defined cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications.
- CCI-003123 - Implement organization-defined cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.
- CCI-002450 - Implement organization-defined types of cryptography for each specified cryptography use.
- CCI-002418 - Protect the confidentiality and/or integrity of transmitted information.
Weight
10
Fix Recommendation
Configure RHEL 10 to implement FIPS mode.
If this check fails on an installed system, it is a permanent finding until the system is reinstalled with "fips=1" during installation.
Red Hat 10 does not support switching to strict FIPS mode after installation.
Check Contents
Verify RHEL 10 is in FIPS mode with the following command:
$ cat /proc/sys/crypto/fips_enabled
1
If the command does not return "1", this is a finding.
Vulnerability Number
V-281009
Documentable
False
Rule Version
RHEL-10-000500
Severity Override Guidance
Verify RHEL 10 is in FIPS mode with the following command:
$ cat /proc/sys/crypto/fips_enabled
1
If the command does not return "1", this is a finding.
Check Content Reference
M
Target Key
5733