UCF STIG Viewer Logo

The DBMS must be configured on a platform that has a NIST certified FIPS 140-2 installation of OpenSSL.


Overview

Finding ID Version Rule ID IA Controls Severity
V-73071 PGS9-00-012800 SV-87723r1_rule High
Description
Postgres uses OpenSSL for the underlying encryption layer. Currently only Red Hat Enterprise Linux is certified as a FIPS 140-2 distribution of OpenSSL. For other operating systems, users must obtain or build their own FIPS 140-2 OpenSSL libraries.
STIG Date
PostgreSQL 9.x Security Technical Implementation Guide 2017-01-20

Details

Check Text ( C-73205r1_chk )
If the deployment incorporates a custom build of the operating system and Postgres guaranteeing the use of FIPS 140-2- compliant OpenSSL, this is not a finding.

If the Postgres Plus Advanced Server is not installed on Red Hat Enterprise Linux (RHEL), this is a finding.

If FIPS encryption is not enabled, this is a finding.
Fix Text (F-79517r1_fix)
Install Postgres with FIPS-compliant cryptography enabled on RHEL; or by other means ensure that FIPS 140-2 certified OpenSSL libraries are used by the DBMS.