STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 9 Security Technical Implementation Guide Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

RHEL 9 must use the common access card (CAC) smart card driver.

DISA Rule

SV-258121r1155682_rule

Vulnerability Number

V-258121

Group Title

SRG-OS-000104-GPOS-00051

Rule Version

RHEL-09-611160

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure RHEL 9 to load the CAC driver.

$ sudo opensc-tool --set-conf-entry app:default:card_drivers:cac

Restart the pcscd service to apply the changes:

$ sudo systemctl restart pcscd

Check Contents

Verify RHEL loads the CAC driver with the following command:

$ sudo opensc-tool --get-conf-entry app:default:card_drivers

cac

If "cac" is not listed as a card driver, or no line is returned for "card_drivers", this is a finding.

Vulnerability Number

V-258121

Documentable

False

Rule Version

RHEL-09-611160

Severity Override Guidance

Verify RHEL loads the CAC driver with the following command:

$ sudo opensc-tool --get-conf-entry app:default:card_drivers

cac

If "cac" is not listed as a card driver, or no line is returned for "card_drivers", this is a finding.

Check Content Reference

M

Target Key

5551