SV-283446r1188530_rule
V-283446
SRG-OS-000033-GPOS-00014
OL08-00-010182
CAT I
10
Configure OL 8 to implement DOD-approved encryption by following the steps below:
To enable strict FIPS compliance, the fips=1 kernel option must be added to the kernel boot parameters during system installation so that key generation is done with FIPS-approved algorithms and continuous monitoring tests in place.
Enable FIPS mode after installation (not strict FIPS-compliant) with the following command:
$ sudo fips-mode-setup --enable
Reboot the system for the changes to take effect.
Verify OL 8 implements DOD-approved encryption to protect the confidentiality of remote access sessions.
Show the configured systemwide cryptographic policy by running the following command:
$ sudo update-crypto-policies --show
FIPS
If the main policy name is not "FIPS", this is a finding.
If the AD-SUPPORT subpolicy module is included (e.g., "FIPS:AD-SUPPORT"), and Active Directory support is not documented as an operational requirement with the information system security officer (ISSO), this is a finding.
If the NO-ENFORCE-EMS subpolicy module is included (e.g., "FIPS:NO-ENFORCE-EMS"), and not enforcing EMS is not documented as an operational requirement with the ISSO, this is a finding.
If any other subpolicy module is included, this is a finding.
V-283446
False
OL08-00-010182
Verify OL 8 implements DOD-approved encryption to protect the confidentiality of remote access sessions.
Show the configured systemwide cryptographic policy by running the following command:
$ sudo update-crypto-policies --show
FIPS
If the main policy name is not "FIPS", this is a finding.
If the AD-SUPPORT subpolicy module is included (e.g., "FIPS:AD-SUPPORT"), and Active Directory support is not documented as an operational requirement with the information system security officer (ISSO), this is a finding.
If the NO-ENFORCE-EMS subpolicy module is included (e.g., "FIPS:NO-ENFORCE-EMS"), and not enforcing EMS is not documented as an operational requirement with the ISSO, this is a finding.
If any other subpolicy module is included, this is a finding.
M
5416