Red Hat Enterprise Linux 9 • Release: 7 Benchmark Date: 05 Jan 2026

CAT II V-257954 RHEL-09-252065

RHEL 9 libreswan package must be installed.

Documentable No
Rule ID SV-257954r1106315_rule
CCI References
CCI-000803

Providing the ability for remote users or systems to initiate a secure VPN connection protects information when it is transmitted over a wide area network. Satisfies: SRG-OS-000480-GPOS-00227, SRG-OS-000120-GPOS-00061

Check Procedure

Note: If there is no operational need for Libreswan to be installed, this rule is not applicable.

Verify that RHEL 9 libreswan service package is installed.

Check that the libreswan service package is installed with the following command:

$ dnf list --installed libreswan

Example output:

libreswan.x86_64          4.6-3.el9

If the "libreswan" package is not installed, this is a finding.

Fix Action

Install the libreswan service (if it is not already installed) with the following command:

$ sudo dnf install libreswan