OL09-00-002404 - OL 9 IP tunnels must use 140-3 approved cryptographic algorithms.

Information

Overriding the system crypto policy makes the behavior of the Libreswan service violate expectations and makes system configuration more fragmented.

Solution

Configure IPsec to use the systemwide cryptographic policy.

Add the following line to "/etc/ipsec.conf":

include /etc/crypto-policies/back-ends/libreswan.config

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_9_V1R2_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(2), CAT|II, CCI|CCI-000068, Rule-ID|SV-271743r1092635_rule, STIG-ID|OL09-00-002404, Vuln-ID|V-271743

Plugin: Unix

Control ID: ec2cafa893b04ad711dab667a109b19d4bf325083908d9622831e24a33e4db12