Check: SOL-11.1-060190
Solaris 11 SPARC STIG:
SOL-11.1-060190
(in versions v2 r10 through v1 r10)
Title
The operating system must protect the integrity of transmitted information. (Cat II impact)
Discussion
Ensuring the integrity of transmitted information requires the operating system take feasible measures to employ transmission layer security. This requirement applies to communications across internal and external networks.
Check Content
The operator shall determine if IPsec is being used to encrypt data for activities such as cluster interconnects or other non-SSH, SFTP data connections. On both systems review the file /etc/inet/ipsecinit.conf. Ensure that connections between hosts are configured properly in this file per the Solaris 11 documentation. Check that the IPsec policy service is online: # svcs svc:/network/ipsec/policy:default If the IPsec service is not online, this is a finding. If encrypted protocols are not used between systems, this is a finding.
Fix Text
The Service Management profile is required. Configure IPsec encrypted tunneling between two systems. On both systems review the file /etc/inet/ipsecinit.conf. Ensure that connections between hosts are configured properly in this file per the Solaris 11 documentation. Ensure that the IPsec policy service is online: Enable the IPsec service: # svcadm enable svc:/network/ipsec/policy:default
Additional Identifiers
Rule ID: SV-219984r854543_rule
Vulnerability ID: V-219984
Group Title: SRG-OS-000423
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001127 |
The information system protects the integrity of transmitted information. |
CCI-002418 |
The information system protects the confidentiality and/or integrity of transmitted information. |
Controls
Number | Title |
---|---|
SC-8 |
Transmission Confidentiality And Integrity |