STIGQter STIGQter: STIG Summary: Tri-Lab Operating System Stack (TOSS) 4 Security Technical Implementation Guide Version: 2 Release: 6 Benchmark Date: 01 Jul 2026:

TOSS must accept Personal Identity Verification (PIV) credentials.

DISA Rule

SV-253090r958816_rule

Vulnerability Number

V-253090

Group Title

SRG-OS-000376-GPOS-00161

Rule Version

TOSS-04-040420

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure TOSS to accept PIV credentials.

Install the "opensc" package using the following command:

$ sudo yum install opensc

Check Contents

Verify TOSS accepts PIV credentials.

Check that the "opensc" package is installed on the system with the following command:

$ sudo yum list installed opensc

opensc.x86_64 0.20.0-4.el8 @anaconda

Check that "opensc" accepts PIV cards with the following command:

$ sudo opensc-tool --list-drivers | grep -i piv

PIV-II Personal Identity Verification Card

If the "opensc" package is not installed and the "opensc-tool" driver list does not include "PIV-II", this is a finding.

Vulnerability Number

V-253090

Documentable

False

Rule Version

TOSS-04-040420

Severity Override Guidance

Verify TOSS accepts PIV credentials.

Check that the "opensc" package is installed on the system with the following command:

$ sudo yum list installed opensc

opensc.x86_64 0.20.0-4.el8 @anaconda

Check that "opensc" accepts PIV cards with the following command:

$ sudo opensc-tool --list-drivers | grep -i piv

PIV-II Personal Identity Verification Card

If the "opensc" package is not installed and the "opensc-tool" driver list does not include "PIV-II", this is a finding.

Check Content Reference

M

Target Key

5469