Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-73071 | PGS9-00-012800 | SV-87723r1_rule | High |
Description |
---|
Postgres uses OpenSSL for the underlying encryption layer. Currently only Red Hat Enterprise Linux is certified as a FIPS 140-2 distribution of OpenSSL. For other operating systems, users must obtain or build their own FIPS 140-2 OpenSSL libraries. |
STIG | Date |
---|---|
PostgreSQL 9.x Security Technical Implementation Guide | 2017-01-20 |
Check Text ( C-73205r1_chk ) |
---|
If the deployment incorporates a custom build of the operating system and Postgres guaranteeing the use of FIPS 140-2- compliant OpenSSL, this is not a finding. If the Postgres Plus Advanced Server is not installed on Red Hat Enterprise Linux (RHEL), this is a finding. If FIPS encryption is not enabled, this is a finding. |
Fix Text (F-79517r1_fix) |
---|
Install Postgres with FIPS-compliant cryptography enabled on RHEL; or by other means ensure that FIPS 140-2 certified OpenSSL libraries are used by the DBMS. |