Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-213668 | PPS9-00-013200 | SV-213668r508024_rule | High |
Description |
---|
Postgres uses OpenSSL for the underlying encryption layer. Currently only Red Hat Enterprise Linux is certified as a FIPS 140-2 distribution of OpenSSL. For other operating systems, users must obtain or build their own FIPS 140-2 OpenSSL libraries. |
STIG | Date |
---|---|
EDB Postgres Advanced Server Security Technical Implementation Guide | 2020-09-23 |
Check Text ( C-14890r290316_chk ) |
---|
If the Postgres Plus Advanced Server is not installed on Red Hat Enterprise Linux (RHEL), this is a finding. |
Fix Text (F-14888r290317_fix) |
---|
Install Postgres Plus Advanced Server on RHEL or ensure that FIPS 140-2 certified OpenSSL libraries are used by the DBMS. |