Unapproved mechanisms used for authentication to the cryptographic module are not verified and therefore, cannot be relied upon to provide confidentiality or integrity, and DoW data may be compromised.
RHEL 8 systems utilizing encryption are required to use FIPS-compliant mechanisms for authenticating to cryptographic modules.
Currently, Kerberos does not utilize FIPS 140-2 cryptography.
FIPS 140-2 is the current standard for validating that mechanisms used to access cryptographic modules utilize authentication that meets DoW requirements. This allows for Security Levels 1, 2, 3, or 4 for use on a general-purpose computing system.
Check
Verify the krb5-server package has not been installed on the system with the following commands:
If the system is a workstation or is utilizing krb5-server-1.17-18.el8.x86_64 or newer, this is Not Applicable
$ sudo yum list installed krb5-server
krb5-server.x86_64 1.17-9.el8 repository
If the krb5-server package is installed and is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.
Fix
Document the krb5-server package with the ISSO as an operational requirement or remove it from the system with the following command: