diff --git a/linux_os/guide/services/rng/service_rngd_enabled/policy/stig/shared.yml b/linux_os/guide/services/rng/service_rngd_enabled/policy/stig/shared.yml deleted file mode 100644 index 5b2a3384d6e..00000000000 --- a/linux_os/guide/services/rng/service_rngd_enabled/policy/stig/shared.yml +++ /dev/null @@ -1,25 +0,0 @@ -srg_requirement: |- - {{{ full_name }}} must enable the hardware random number generator entropy gatherer service. - -vuldiscussion: |- - The most important characteristic of a random number generator is its randomness, namely its ability to deliver random numbers that are impossible to predict. Entropy in computer security is associated with the unpredictability of a source of randomness. The random source with high entropy tends to achieve a uniform distribution of random values. Random number generators are one of the most important building blocks of cryptosystems. - - The rngd service feeds random data from hardware device to kernel random device. Quality (non-predictable) random number generation is important for several security functions (i.e., ciphers). - -checktext: |- - Verify that {{{ full_name }}} has enabled the hardware random number generator entropy gatherer service with the following command: - - $ systemctl is-active rngd - - active - - If the "rngd" service is not active, this is a finding. - -fixtext: |- - Install the rng-tools package with the following command: - - $ sudo dnf install rng-tools - - Then enable the rngd service run the following command: - - $ sudo systemctl enable --now rngd