ALMA-09-003870 - AlmaLinux OS 9 IP tunnels must use FIPS 140-3 approved cryptographic algorithms.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Overriding the system crypto policy makes the behavior of the Libreswan service violate expectations and makes the system configuration more fragmented.

Solution

Configure Libreswan to use the systemwide cryptographic policy.

Add the following line to "/etc/ipsec.conf":

include /etc/crypto-policies/back-ends/libreswan.config

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CL_AlmaLinux_OS_9_V1R1_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000068, Rule-ID|SV-269122r1050004_rule, STIG-ID|ALMA-09-003870, Vuln-ID|V-269122

Plugin: Unix

Control ID: f3f4b2b50ab37843282d7405b71a4c5acc354c21e5a19936dcb8344256688c6b