STIGUI
V-282615CAT I — High severitySV-282615r1201495_rule

TOSS 5 crypto policy files must match files shipped with the operating system.

Rule version TOSS-05-000469 · STIG v1 · 2026-08-20

Discussion

The TOSS 5 package "crypto-policies" defines the cryptography policies for the system.

If the files are changed from those shipped with the operating system, it may be possible for TOSS 5 to use cryptographic functions that are not FIPS 140-3 approved.

Check

Verify the TOSS 5 package "crypto-policies" has not been modified using the following command:

$ rpm -V crypto-policies

If the command has any output, this is a finding.

Fix

Reinstall the "crypto-policies" package to remove any modifications.

$ sudo dnf reinstall crypto-policies

Identifiers

Group ID
V-282615
Group title
SRG-OS-000478-GPOS-00223
Rule ID
SV-282615r1201495_rule
Check ID
C-87176r1200823_chk
Fix ID
F-87081r1200824_fix