[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256288

 
 

909

 
 

199146

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-99418-8

Platform: cpe:/o:redhat:enterprise_linux:9Date: (C)2023-07-04   (M)2023-07-04



The system-wide crypto-policies followed by the crypto core components allow consistently deprecating and disabling algorithms system-wide.Rationale:If the Legacy system-wide crypto policy is selected, it includes support for TLS 1.0, TLS 1.1, and SSH2 protocols or later. The algorithms DSA, 3DES, and RC4 are allowed, while RSA and Diffie-Hellman parameters are accepted if larger than 1023-bits.These legacy protocols and algorithms can make the system vulnerable to attacks, including those listed in RFC 7457Audit:Run the following command to verify that the system-wide crypto policy is not LEGACY# grep -E -i `^s*LEGACYs*(s+#.*)?$` /etc/crypto-policies/configFix:Run the following command to change the system-wide crypto policy# update-crypto-policies --set DEFAULT# update-crypto-policies


Parameter:

[DEFAULT/LEGACY (Not recommended)/FUTURE/FIPS]


Technical Mechanism:

Run the following command to change the system-wide crypto policy # update-crypto-policies --set DEFAULT # update-crypto-policies

CCSS Severity:CCSS Metrics:
CCSS Score : 7.3Attack Vector: LOCAL
Exploit Score: 1.8Attack Complexity: LOW
Impact Score: 5.5Privileges Required: LOW
Severity: HIGHUser Interaction: NONE
Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:HScope: UNCHANGED
 Confidentiality: LOW
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:86913


OVAL    1
oval:org.secpod.oval:def:86913
XCCDF    1
xccdf_org.secpod_benchmark_general_RHEL_9

© SecPod Technologies