SV-282444r1200312_rule
V-282444
SRG-OS-000068-GPOS-00036
TOSS-05-000367
CAT II
10
Configure TOSS 5 to map the authenticated identity to the user or group account by adding or modifying the certmap section of the "/etc/sssd/sssd.conf" file based on the following example:
[certmap/testing.test/rule_name]
matchrule = .*EDIPI@mil
maprule = (userCertificate;binary={cert!bin})
dmains = testing.test
Restart the "sssd" service for the changes to take effect. To restart the "sssd" service, run the following command:
$ sudo systemctl restart sssd.service
Verify the certificate of the user or group is mapped to the corresponding user or group in the "sssd.conf" file using the following command:
$ sudo cat /etc/sssd/sssd.conf
[certmap/testing.test/rule_name]
matchrule =<SAN>.*EDIPI@mil
maprule = (userCertificate;binary={cert!bin})
domains = testing.test
If the certmap section does not exist, ask the system administrator (SA) to indicate how certificates are mapped to accounts. If there is no evidence of certificate mapping, this is a finding.
V-282444
False
TOSS-05-000367
Verify the certificate of the user or group is mapped to the corresponding user or group in the "sssd.conf" file using the following command:
$ sudo cat /etc/sssd/sssd.conf
[certmap/testing.test/rule_name]
matchrule =<SAN>.*EDIPI@mil
maprule = (userCertificate;binary={cert!bin})
domains = testing.test
If the certmap section does not exist, ask the system administrator (SA) to indicate how certificates are mapped to accounts. If there is no evidence of certificate mapping, this is a finding.
M
5738