Rule ID
SV-282386r1200138_rule
Version
V1R1
CCIs
Overriding the system crypto policy makes the behavior of the Libreswan service violate expectations and makes system configuration more fragmented.
Verify the IPsec service uses the system crypto policy using the following command: Note: If the IPsec service is not installed, this requirement is not applicable. $ sudo grep include /etc/ipsec.conf /etc/ipsec.d/*.conf /etc/ipsec.conf:include /etc/crypto-policies/back-ends/libreswan.config If the ipsec configuration file does not contain "include /etc/crypto-policies/back-ends/libreswan.config", this is a finding.
Configure Libreswan to use the system cryptographic policy. Add the following line to "/etc/ipsec.conf": include /etc/crypto-policies/back-ends/libreswan.config