The Photon operating system TDNF package management tool must cryptographically verify the authenticity of all software packages during installation for all repos.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-258864
PHTN-40-000199
SV-258864r1003651_rule
High
Description
Installation of any nontrusted software, patches, service packs, device drivers, or operating system components can significantly affect the overall security of the operating system. This requirement ensures the software has not been tampered with and has been provided by a trusted vendor.