Rule version TOSS-05-000469 · STIG v1 · 2026-08-20
The TOSS 5 package "crypto-policies" defines the cryptography policies for the system.
If the files are changed from those shipped with the operating system, it may be possible for TOSS 5 to use cryptographic functions that are not FIPS 140-3 approved.
Verify the TOSS 5 package "crypto-policies" has not been modified using the following command:
$ rpm -V crypto-policies
If the command has any output, this is a finding.
Reinstall the "crypto-policies" package to remove any modifications.
$ sudo dnf reinstall crypto-policies