1.2.2 Verify Red Hat GPG Key is Installed

Information

Red Hat cryptographically signs updates with a GPG key to verify that they are valid.

Rationale:

It is important to ensure that updates are obtained from a valid source to protect against spoofing that could lead to the inadvertent installation of malware on the system.

Solution

Compare the GPG fingerprint with the one from Red Hat's web site at http://www.redhat.com/security/team/key. The following command can be used to print the installed release key's fingerprint, which is actually contained in the file referenced below:

# gpg --quiet --with-fingerprint /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release

More information on package signing is also available at https://access.redhat.com/security/team/key.

Default Value:

OS Default: N/A

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2c., CSCv7|3.4, CSCv7|3.5

Plugin: Unix

Control ID: 867d84838eed40d9b468f79adf90814c2cf73a49eee0ce5e0df5dacc2a4be1ec