1.2.3 Ensure gpgcheck is globally activated

Information

The gpgcheck option, found in the main section of the /etc/zypp/zypp.conf and individual /etc/zypp/repos.d/*.repo files determines if an RPM package's signature is checked prior to its installation.

Rationale:

It is important to ensure that an RPM's package signature is always checked prior to installation to ensure that the software is obtained from a trusted source.

Solution

Edit /etc/zypp/zypp.conf and set 'gpgcheck=1' in the [main] section.

Edit any failing files in /etc/zypp/repos.d/*.repo and set all instances of gpgcheck to 1.

See Also

https://workbench.cisecurity.org/files/3675

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4

Plugin: Unix

Control ID: 034a7ea0b63c7655467d34a1d23a6876f7232905765a87e7c4873da5d9145c31