SV-258122r1045246_rule
V-258122
SRG-OS-000375-GPOS-00160
RHEL-09-611165
CAT II
10
Edit the file "/etc/sssd/sssd.conf" or a configuration file in "/etc/sssd/conf.d" and add or edit the following line:
pam_cert_auth = True
Note: If the system administrator (SA) demonstrates the use of an approved alternate multifactor authentication method, this requirement is Not Applicable.
To verify that RHEL 9 has smart cards enabled in System Security Services Daemon (SSSD), run the following command:
$ sudo grep -ir pam_cert_auth /etc/sssd/sssd.conf /etc/sssd/conf.d/
pam_cert_auth = True
If "pam_cert_auth" is not set to "True", the line is commented out, or the line is missing, this is a finding.
V-258122
False
RHEL-09-611165
Note: If the system administrator (SA) demonstrates the use of an approved alternate multifactor authentication method, this requirement is Not Applicable.
To verify that RHEL 9 has smart cards enabled in System Security Services Daemon (SSSD), run the following command:
$ sudo grep -ir pam_cert_auth /etc/sssd/sssd.conf /etc/sssd/conf.d/
pam_cert_auth = True
If "pam_cert_auth" is not set to "True", the line is commented out, or the line is missing, this is a finding.
M
5551