RHEL 10 must have the "subscription-manager" package installed.

STIG ID: RHEL-10-200500  |  SRG: SRG-OS-000366-GPOS-00153 |  Severity: medium (CAT II)  |  CCI: CCI-003992 |  Vulnerability Id: V-280952

Vulnerability Discussion

The Red Hat Subscription Manager application manages software subscriptions and software repositories for installed software products on the local system. It communicates with backend servers, such as the Red Hat Customer Portal or an on-premise instance of Subscription Asset Manager, to register the local system and grant access to software resources determined by the subscription entitlement.

Check

Note: If the system is not an internet connected system, this requirement is not applicable.

Verify RHEL 10 has the "subscription-manager" package installed with the following command:

$ sudo dnf list --installed subscription-manager
Installed Packages
subscription-manager.x86_64 1.30.6.1-1.el10_0 @rhel-10-for-x86_64-baseos-rpms

If the "subscription-manager" package is not installed, this is a finding.

Fix

Configure RHEL 10 to have the "subscription-manager" package installed with the following command:

$ sudo dnf -y install subscription-manager