STIGQter STIGQter: STIG Summary: Amazon Linux 2023 Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 01 Jul 2026:

Amazon Linux 2023 must enable certificate-based smart card authentication.

DISA Rule

SV-274059r1120165_rule

Vulnerability Number

V-274059

Group Title

SRG-OS-000375-GPOS-00160

Rule Version

AZLX-23-001290

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Amazon Linux 2023 to have smart cards enabled in SSSD.

Edit the file "/etc/sssd/sssd.conf" or a configuration file in "/etc/sssd/conf.d" and add or edit the following line:

pam_cert_auth = True

Check Contents

Note: If the system administrator demonstrates the use of an approved alternate multifactor authentication method, this requirement is not applicable.

Verify Amazon Linux 2023 has smart cards enabled in System Security Services Daemon (SSSD), run the following command:

$ sudo grep -ir pam_cert_auth /etc/sssd/sssd.conf /etc/sssd/conf.d/
/etc/sssd/sssd.conf:pam_cert_auth = True

If "pam_cert_auth" is not set to "True", the line is commented out, or the line is missing, this is a finding.

Vulnerability Number

V-274059

Documentable

False

Rule Version

AZLX-23-001290

Severity Override Guidance

Note: If the system administrator demonstrates the use of an approved alternate multifactor authentication method, this requirement is not applicable.

Verify Amazon Linux 2023 has smart cards enabled in System Security Services Daemon (SSSD), run the following command:

$ sudo grep -ir pam_cert_auth /etc/sssd/sssd.conf /etc/sssd/conf.d/
/etc/sssd/sssd.conf:pam_cert_auth = True

If "pam_cert_auth" is not set to "True", the line is commented out, or the line is missing, this is a finding.

Check Content Reference

M

Target Key

5700