V-38487: The system package management tool must cryptographically verify the authenticity of all software packages during installation. ---------------------------------------------------------------------------------------------------------------------------------------- Ensuring all packages' cryptographic signatures are valid prior to installation ensures the provenance of the software and protects against malicious tampering. Details: `V-38487 in STIG Viewer`_. .. _V-38487 in STIG Viewer: https://www.stigviewer.com/stig/red_hat_enterprise_linux_6/2015-05-26/finding/V-38487 Notes for deployers ~~~~~~~~~~~~~~~~~~~ .. include:: developer-notes/V-38487.rst