The system must verify that package updates are digitally signed.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-219997 | SOL-11.1-020020 | SV-219997r1016296_rule | CCI-003992 | medium |
| Description | ||||
| Digitally signed packages ensure that the source of the package can be identified. | ||||
| STIG | Date | |||
| Solaris 11 X86 Security Technical Implementation Guide | 2025-05-05 | |||
Details
Check Text (C-219997r1016296_chk)
Determine what the signature policy is for pkg publishers:
# pkg property | grep signature-policy
Check that output produces:
signature-policy verify
If the output does not confirm that signature-policy verify is active, this is a finding.
Fix Text (F-21706r372521_fix)
The Software Installation Profile is required.
Configure the package system to ensure that digital signatures are verified.
# pfexec pkg set-property signature-policy verify