Rule ID
SV-282503r1200489_rule
Version
V1R1
CCIs
Overriding the system crypto policy makes the behavior of Kerberos violate expectations and makes system configuration more fragmented.
Verify the symlink exists and targets the correct Kerberos crypto policy, using the following command: file /etc/crypto-policies/back-ends/krb5.config If command output shows the following line, Kerberos is configured to use the systemwide crypto policy: /etc/crypto-policies/back-ends/krb5.config: symbolic link to /usr/share/crypto-policies/FIPS/krb5.txt If the symlink does not exist or points to a different target, this is a finding.
Configure Kerberos to use system crypto policy. Create a symlink pointing to system crypto policy in the Kerberos configuration using the following command: $ sudo ln -s /etc/crypto-policies/back-ends/krb5.config /usr/share/crypto-policies/FIPS/krb5.txt