UCF STIG Viewer Logo

The SNMP service must require the use of a FIPS 140-2 approved encryption algorithm for protecting the privacy of SNMP messages.


Overview

Finding ID Version Rule ID IA Controls Severity
V-22449 GEN005307 SV-45952r1_rule Medium
Description
The SNMP service must use AES or a FIPS 140-2 approved successor algorithm for protecting the privacy of communications.
STIG Date
SUSE Linux Enterprise Server v11 for System z Security Technical Implementation Guide 2018-09-19

Details

Check Text ( C-43241r1_chk )
Verify the SNMP daemon uses AES for SNMPv3 users.

Procedure:
Examine the default install location /etc/snmp/snmpd.conf
or:
# find / -name snmpd.conf


# grep -v '^#' | grep -i createuser | grep -vi AES
If any line is present this is a finding.
Fix Text (F-39320r1_fix)
Edit /etc/snmp/snmpd.conf and add the AES keyword for any create user statement without one.
Restart the SNMP service.
# service snmpd restart