STIGUI
V-282503CAT II — Medium severitySV-282503r1200489_rule

TOSS 5 must use mechanisms meeting the requirements of applicable federal laws, executive orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module.

Rule version TOSS-05-000471 · STIG v1 · 2026-08-20

Discussion

Overriding the system crypto policy makes the behavior of Kerberos violate expectations and makes system configuration more fragmented.

Check

Verify the symlink exists and targets the correct Kerberos crypto policy, using the following command:

file /etc/crypto-policies/back-ends/krb5.config

If command output shows the following line, Kerberos is configured to use the systemwide crypto policy:

/etc/crypto-policies/back-ends/krb5.config: symbolic link to /usr/share/crypto-policies/FIPS/krb5.txt

If the symlink does not exist or points to a different target, this is a finding.

Fix

Configure Kerberos to use system crypto policy.

Create a symlink pointing to system crypto policy in the Kerberos configuration using the following command:

$ sudo ln -s /etc/crypto-policies/back-ends/krb5.config /usr/share/crypto-policies/FIPS/krb5.txt

Identifiers

Group ID
V-282503
Group title
SRG-OS-000120-GPOS-00061
Rule ID
SV-282503r1200489_rule
Check ID
C-87064r1200487_chk
Fix ID
F-86969r1200488_fix