V-38476: Vendor-provided cryptographic certificates must be installed to verify the integrity of system software. ----------------------------------------------------------------------------------------------------------------- The Red Hat GPG keys are necessary to cryptographically verify packages are from Red Hat. Details: `V-38476 in STIG Viewer`_. .. _V-38476 in STIG Viewer: https://www.stigviewer.com/stig/red_hat_enterprise_linux_6/2015-05-26/finding/V-38476 Notes for deployers ~~~~~~~~~~~~~~~~~~~ .. include:: developer-notes/V-38476.rst