STIGQter STIGQter: STIG Summary: Canonical Ubuntu 20.04 LTS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 Mar 2021:

The Ubuntu operating system must implement smart card logins for multifactor authentication for local and network access to privileged and non-privileged accounts.

DISA Rule

SV-238210r653805_rule

Vulnerability Number

V-238210

Group Title

SRG-OS-000105-GPOS-00052

Rule Version

UBTU-20-010033

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Ubuntu operating system to use multifactor authentication for network access to accounts.

Add or update "pam_pkcs11.so" in "/etc/pam.d/common-auth" to match the following line:

auth [success=2 default=ignore] pam_pkcs11.so

Set the sshd option "PubkeyAuthentication yes" in the "/etc/ssh/sshd_config" file.

Check Contents

Verify the Ubuntu operating system has the packages required for multifactor authentication installed with the following commands:

$ dpkg -l | grep libpam-pkcs11

ii libpam-pkcs11 0.6.8-4 amd64 Fully featured PAM module for using PKCS#11 smart cards

If the "libpam-pkcs11" package is not installed, this is a finding.

Verify the sshd daemon allows public key authentication with the following,

$ grep ^Pubkeyauthentication /etc/ssh/sshd_config

PubkeyAuthentication yes

If this option is set to "no" or is missing, this is a finding.

Vulnerability Number

V-238210

Documentable

False

Rule Version

UBTU-20-010033

Severity Override Guidance

Verify the Ubuntu operating system has the packages required for multifactor authentication installed with the following commands:

$ dpkg -l | grep libpam-pkcs11

ii libpam-pkcs11 0.6.8-4 amd64 Fully featured PAM module for using PKCS#11 smart cards

If the "libpam-pkcs11" package is not installed, this is a finding.

Verify the sshd daemon allows public key authentication with the following,

$ grep ^Pubkeyauthentication /etc/ssh/sshd_config

PubkeyAuthentication yes

If this option is set to "no" or is missing, this is a finding.

Check Content Reference

M

Target Key

5318

Comments