SV-269372r1050617_rule
V-269372
SRG-OS-000375-GPOS-00160
ALMA-09-033790
CAT II
10
Edit the file "/etc/sssd/sssd.conf" or a "*.conf" file within the "/etc/sssd/conf.d/" directory and add or edit the following line within the [pam] section:
pam_cert_auth = True
Note: If the System Administrator demonstrates the use of an approved alternate multifactor authentication method, this requirement is Not Applicable.
Verify that AlmaLinux OS 9 has smart cards are enabled in System Security Services Daemon (SSSD), run the following command:
$ grep pam_cert_auth /etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf
/etc/sssd/conf.d/certificate_verification.conf:pam_cert_auth = True
If "pam_cert_auth" is not set to "True", the line is commented out, or the line is missing, this is a finding.
V-269372
False
ALMA-09-033790
Note: If the System Administrator demonstrates the use of an approved alternate multifactor authentication method, this requirement is Not Applicable.
Verify that AlmaLinux OS 9 has smart cards are enabled in System Security Services Daemon (SSSD), run the following command:
$ grep pam_cert_auth /etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf
/etc/sssd/conf.d/certificate_verification.conf:pam_cert_auth = True
If "pam_cert_auth" is not set to "True", the line is commented out, or the line is missing, this is a finding.
M
5664