1.2.1 Ensure update server certificate key fingerprints are configured

Information

FreeBSD downloads binary updates from an update server and uses Public Key Infrastructure to verify the downloads. This key fingerprint is used in the file /etc/freebsd-update.conf . This key fingerprint varies between different versions of FreeBSD and must be validated manually.

Ensure that updates are obtained from a valid source to protect against spoofing that could lead to the inadvertent installation of malware on the system. Verify the key fingerprint being used is correctly configured in the file /etc/freebsd-update.conf.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

If the previous outputs of the commands are not identical, there is a high possibility that something is wrong with the system. The verification of certificates might fail for various reasons, but the most common issue is improper date and time. Or in case the version of FreeBSD is too old and the specific running version has not been updated for a long time. Check the date and time before proceeding further.

Impact:

By downloading updates from the wrong server there is the possibility that someone is injecting malicious content in the base operating system.

See Also

https://workbench.cisecurity.org/benchmarks/19044

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4

Plugin: Unix

Control ID: 919b7f6608c7309f0ee52cd0b88f994d4ae4e266c6bb6a2e6dd37cb571dec984