UCF STIG Viewer Logo

The system package management tool must cryptographically verify the authenticity of software packages during installation.


Overview

Finding ID Version Rule ID IA Controls Severity
V-22588 GEN008800 SV-26991r1_rule ECSC-1 Low
Description
To prevent the installation of software from unauthorized sources, the system package management tool must use cryptographic algorithms to verify the packages are authentic.
STIG Date
SOLARIS 9 SPARC SECURITY TECHNICAL IMPLEMENTATION GUIDE 2015-10-01

Details

Check Text ( C-27934r1_chk )
Verify package signature validation is not disabled.
# grep "authentication=quit" /var/sadm/install/admin/default
If no configuration is returned, this is a finding.
Fix Text (F-24257r1_fix)
Edit /var/sadm/install/admin/default and set the authentication setting to quit.