RHEL 9 must have the packages required for encrypting offloaded audit logs installed.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-258141 | RHEL-09-652015 | SV-258141r1045280_rule | CCI-000803 | medium |
| Description | ||||
| The rsyslog-gnutls package provides Transport Layer Security (TLS) support for the rsyslog daemon, which enables secure remote logging. Satisfies: SRG-OS-000480-GPOS-00227, SRG-OS-000120-GPOS-00061 | ||||
| STIG | Date | |||
| Red Hat Enterprise Linux 9 Security Technical Implementation Guide | 2025-05-14 | |||
Details
Check Text (C-258141r1045280_chk)
Verify that RHEL 9 has the rsyslog-gnutls package installed with the following command:
$ dnf list --installed rsyslog-gnutls
Example output:
rsyslog-gnutls.x86_64 8.2102.0-101.el9_0.1
If the "rsyslog-gnutls" package is not installed, this is a finding.
Fix Text (F-61806r926409_fix)
The rsyslog-gnutls package can be installed with the following command:
$ sudo dnf install rsyslog-gnutls