STIGUI
V-282386CAT I — High severitySV-282386r1200138_rule

TOSS 5 IP tunnels must use FIPS 140-3-approved cryptographic algorithms.

Rule version TOSS-05-000466 · STIG v1 · 2026-08-20

Discussion

Overriding the system crypto policy makes the behavior of the Libreswan service violate expectations and makes system configuration more fragmented.

Check

Verify the IPsec service uses the system crypto policy using the following command:

Note: If the IPsec service is not installed, this requirement is not applicable.

$ sudo grep include /etc/ipsec.conf /etc/ipsec.d/*.conf

/etc/ipsec.conf:include /etc/crypto-policies/back-ends/libreswan.config

If the ipsec configuration file does not contain "include /etc/crypto-policies/back-ends/libreswan.config", this is a finding.

Fix

Configure Libreswan to use the system cryptographic policy.

Add the following line to "/etc/ipsec.conf":

include /etc/crypto-policies/back-ends/libreswan.config

Identifiers

Group ID
V-282386
Group title
SRG-OS-000033-GPOS-00014
Rule ID
SV-282386r1200138_rule
Check ID
C-86947r1200136_chk
Fix ID
F-86852r1200137_fix