| name | cis-ubuntu2004-v300-1-2-1-1 |
| description | Ensure GPG keys are configured |
| category | cis-storage |
| version | 3.0.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-20.04","package-management","gpg","integrity"] |
| cis_id | 1.2.1.1 |
| cis_benchmark | CIS Ubuntu Linux 20.04 LTS Benchmark v3.0.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
1.2.1.1 Ensure GPG keys are configured (Manual)
Profile
- Level 1 - Server
- Level 1 - Workstation
Description
Most package managers implement GPG key signing to verify package integrity during installation.
Rationale
It is important to ensure that updates are obtained from a valid source to protect against spoofing that could lead to the inadvertent installation of malware on the system.
Audit Procedure
Command Line
Verify GPG keys are configured correctly for your package manager:
Note:
-
apt-key list is deprecated. Manage keyring files in trusted.gpg.d instead (see apt-key(8)).
-
With the deprecation of apt-key it is recommended to use the Signed-By option in sources.list to require a repository to pass apt-secure(8) verification with a certain set of keys rather than all trusted keys apt has configured.
-
OR -
- Run the following script and verify GPG keys are configured correctly for your package manager:
#!/usr/bin/env bash
{
for file in /etc/apt/trusted.gpg.d/*.{gpg,asc} /etc/apt/sources.list.d/*.{gpg,asc} ; do
if [ -f "$file" ]; then
echo -e "File: $file"
gpg --list-packets "$file" 2>/dev/null | awk '/keyid/ && !seen[$NF]++ {print "keyid:", $NF}'
gpg --list-packets "$file" 2>/dev/null | awk '/Signed-By:/ {print "signed-by:", $NF}'
echo -e
fi
done
}
- REVIEW and VERIFY to ensure that GPG keys are configured correctly for your package manager IAW site policy.