STIGQter STIGQter: STIG Summary: SUSE Linux Enterprise Micro (SLEM) 5 Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 01 Apr 2026:

If Network Security Services (NSS) is being used by SLEM 5 it must prohibit the use of cached authentications after one day.

DISA Rule

SV-261399r996617_rule

Vulnerability Number

V-261399

Group Title

SRG-OS-000383-GPOS-00166

Rule Version

SLEM-05-631010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure NSS, if used by SLEM 5, to prohibit the use of cached authentications after one day.

Add or modify the following line in the "/etc/sssd/sssd.conf" file, below the line "[nss]":

memcache_timeout = 86400

Check Contents

If NSS is used by SLEM 5, verify it prohibits the use of cached authentications after one day with the following command:

Note: If NSS is not used on the operating system, this is not applicable.

> sudo grep -i "memcache_timeout" /etc/sssd/sssd.conf
memcache_timeout = 86400

If "memcache_timeout" has a value greater than "86400", the line is commented out, or the line is missing, this is a finding.

Vulnerability Number

V-261399

Documentable

False

Rule Version

SLEM-05-631010

Severity Override Guidance

If NSS is used by SLEM 5, verify it prohibits the use of cached authentications after one day with the following command:

Note: If NSS is not used on the operating system, this is not applicable.

> sudo grep -i "memcache_timeout" /etc/sssd/sssd.conf
memcache_timeout = 86400

If "memcache_timeout" has a value greater than "86400", the line is commented out, or the line is missing, this is a finding.

Check Content Reference

M

Target Key

5596