1.84 RHEL-10-300070

Information

RHEL 10 must use FIPS 140-3-approved cryptographic algorithms for IP tunnels.

GROUP ID: V-281014RULE ID: SV-281014r1165397

Overriding the systemwide cryptographic policy makes the behavior of the Libreswan service violate expectations and makes system configuration more fragmented.

Solution

Configure RHEL 10 so that Libreswan uses the systemwide cryptographic policy.

Add the following line to "/etc/ipsec.conf":

include /etc/crypto-policies/back-ends/libreswan.config

See Also

https://workbench.cisecurity.org/benchmarks/26403