DISA STIGS Viewer

RHEL 9 libreswan package must be installed.

Overview

Finding ID Version Rule ID IA Controls Severity
V-257954 RHEL-09-252065 SV-257954r1106315_rule   Medium
Description
Providing the ability for remote users or systems to initiate a secure VPN connection protects information when it is transmitted over a wide area network. Satisfies: SRG-OS-000480-GPOS-00227, SRG-OS-000120-GPOS-00061
STIG Date
Red Hat Enterprise Linux 9 Security Technical Implementation Guide 2025-05-14

Details

Check Text (C-61695r1101930_chk)
Note: If there is no operational need for Libreswan to be installed, this rule is not applicable.

Verify that RHEL 9 libreswan service package is installed.

Check that the libreswan service package is installed with the following command:

$ dnf list --installed libreswan

Example output:

libreswan.x86_64 4.6-3.el9

If the "libreswan" package is not installed, this is a finding.
Fix Text (F-61619r925848_fix)
Install the libreswan service (if it is not already installed) with the following command:

$ sudo dnf install libreswan