1. Home
  2. Security Hardening
  3. CIS Amazon Linux V2.1.0 L1
  4. Ensure gpgcheck is globally activated

Ensure gpgcheck is globally activated

Details

It is important to ensure that an RPM’s package signature is always checked prior to installation to ensure that the software is obtained from a trusted source.

Solution

Edit /etc/yum.conf and set ‘gpgcheck=1’ in the [main] section.Edit any failing files in /etc/yum.repos.d/* and set all instances of gpgcheck to ‘1’.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: System and Information Integrity.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles