SV-282583r1200729_rule
V-282583
SRG-OS-000366-GPOS-00153
TOSS-05-000116
CAT I
10
Configure dnf to always check the GPG signature of software packages originating from external software repositories before installation.
Add or update the following line in the [main] section of the /etc/dnf/dnf.conf file:
gpgcheck=1
Verify dnf always checks the GPG signature of software packages originating from external software repositories before installation:
$ grep gpgcheck /etc/dnf/dnf.conf
gpgcheck=1
If "gpgcheck" is not set to "1", or if the option is missing or commented out, ask the system administrator how the GPG signatures of software packages are verified.
If there is no process to verify GPG signatures that is approved by the organization, this is a finding.
V-282583
False
TOSS-05-000116
Verify dnf always checks the GPG signature of software packages originating from external software repositories before installation:
$ grep gpgcheck /etc/dnf/dnf.conf
gpgcheck=1
If "gpgcheck" is not set to "1", or if the option is missing or commented out, ask the system administrator how the GPG signatures of software packages are verified.
If there is no process to verify GPG signatures that is approved by the organization, this is a finding.
M
5738