SV-248685r958452_rule
V-248685
SRG-OS-000068-GPOS-00036
OL08-00-020090
CAT II
10
Configure OL 8 to map the authenticated identity to the user or group account by adding or modifying the "certmap" section of the "/etc/sssd/sssd.conf" file based on the following example:
[certmap/testing.test/rule_name]
matchrule =<SAN>.*EDIPI@mil
maprule = (userCertificate;binary={cert!bin})
domains = testing.test
The "sssd" service must be restarted for the changes to take effect. To restart the "sssd" service, run the following command:
$ sudo systemctl restart sssd.service
Verify the certificate of the user or group is mapped to the corresponding user or group in the "sssd.conf" file with the following command:
Note: If the System Administrator demonstrates the use of an approved alternate multifactor authentication method, this requirement is not applicable.
$ sudo cat /etc/sssd/sssd.conf
[sssd]
config_file_version = 2
services = pam, sudo, ssh
domains = testing.test
[pam]
pam_cert_auth = True
[domain/testing.test]
id_provider = ldap
[certmap/testing.test/rule_name]
matchrule =<SAN>.*EDIPI@mil
maprule = (userCertificate;binary={cert!bin})
domains = testing.test
If the "certmap" section does not exist, this is a finding.
V-248685
False
OL08-00-020090
Verify the certificate of the user or group is mapped to the corresponding user or group in the "sssd.conf" file with the following command:
Note: If the System Administrator demonstrates the use of an approved alternate multifactor authentication method, this requirement is not applicable.
$ sudo cat /etc/sssd/sssd.conf
[sssd]
config_file_version = 2
services = pam, sudo, ssh
domains = testing.test
[pam]
pam_cert_auth = True
[domain/testing.test]
id_provider = ldap
[certmap/testing.test/rule_name]
matchrule =<SAN>.*EDIPI@mil
maprule = (userCertificate;binary={cert!bin})
domains = testing.test
If the "certmap" section does not exist, this is a finding.
M
5416