UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The SNMP service must require the use of a FIPS 140-2 approved cryptographic hash algorithm as part of its authentication and integrity methods.


Overview

Finding ID Version Rule ID IA Controls Severity
V-22448 GEN005306 SV-63407r1_rule DCNR-1 Medium
Description
The SNMP service must use SHA-1 or a FIPS 140-2 approved successor for authentication and integrity.
STIG Date
Oracle Linux 5 Security Technical Implementation Guide 2015-03-26

Details

Check Text ( C-52113r2_chk )
Verify the SNMP daemon uses SHA for SNMPv3 users.

Procedure:
Examine the default install location /etc/snmp/snmpd.conf
or:
# find / -name snmpd.conf

# grep -v '^#' | grep -i createuser | grep -vi SHA
If any line is present this is a finding.
Fix Text (F-54007r1_fix)
Edit /etc/snmp/snmpd.conf and add the SHA keyword for any create user statement without one.

Restart the SNMP service.
# service snmpd restart