Details
Postgres uses OpenSSL for the underlying encryption layer. Currently only Red Hat Enterprise Linux is certified as a FIPS 140-2 distribution of OpenSSL. For other operating systems, users must obtain or build their own FIPS 140-2 OpenSSL libraries.
Solution
Install Postgres Plus Advanced Server on RHEL or ensure that FIPS 140-2 certified OpenSSL libraries are used by the DBMS.
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: Identification and Authentication.This control applies to the following type of system Unix.
References
- 800-53|IA-7
- CAT|I
- CCI|CCI-000803
- Rule-ID|SV-213668r508024_rule
- STIG-ID|PPS9-00-013200
- STIG-Legacy|SV-83689
- STIG-Legacy|V-69085
- Vuln-ID|V-213668