STIGUI
V-282771CAT II — Medium severitySV-282771r1201293_rule

TOSS 5 must provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store.

Rule version TOSS-05-000081 · STIG v1 · 2026-08-20

Discussion

A Trusted Platform Module (TPM) is an example of a hardware-protected data store that can be used to protect cryptographic keys.

Check

Verify TOSS 5 is using the TPM 2.0 hardware with the following command (if TPM 2.0 hardware is available):

$sudo tpm2_pcrread

<multiple SHA keys>

If the command returns a status of "ERROR", and TPM 2.0 hardware is available, this is a finding.

Fix

Configure TOSS 5 to provide protected storage for cryptographic keys by enabling TPM hardware, if available.

Identifiers

Group ID
V-282771
Group title
SRG-OS-000780-GPOS-00240
Rule ID
SV-282771r1201293_rule
Check ID
C-87332r1201291_chk
Fix ID
F-87237r1201292_fix