OL09-00-002424 - OL 9 must use mechanisms meeting the requirements of applicable federal laws, executive orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module.

Information

Overriding the system crypto policy makes the behavior of Kerberos violate expectations and makes system configuration more fragmented.

Solution

Configure Kerberos to use system crypto policy.

Remove incorrect symlink if it exists using the following command:

$ sudo rm /etc/crypto-policies/back-ends/krb5.config

Create a symlink pointing to system crypto policy in the Kerberos configuration using the following command:

$ sudo ln -s /usr/share/crypto-policies/FIPS/krb5.txt /etc/crypto-policies/back-ends/krb5.config

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_9_V1R2_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-7, CAT|II, CCI|CCI-000803, Rule-ID|SV-271762r1091998_rule, STIG-ID|OL09-00-002424, Vuln-ID|V-271762

Plugin: Unix

Control ID: d40bd86a26e6eb0f690d6d1d8742431492f8533c34858c0e501db9e5f463eaa5