STIGQter STIGQter: STIG Summary: Tri-Lab Operating System Stack (TOSS) 5 Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Mar 2026:

TOSS 5 must accept only external credentials that are NIST compliant.

DISA Rule

SV-282768r1201307_rule

Vulnerability Number

V-282768

Group Title

SRG-OS-000745-GPOS-00210

Rule Version

TOSS-05-000027

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Document all NIST-compliant external authenticators in use.

Check Contents

Sites must document external authenticators being used and that they are NIST compliant.

The following command will verify that Kerberos is functional and produce the list of signing hosts:

$ sudo klist -ekt /etc/krb5.keytab

If external authenticators are being use that are not documented and are not NIST compliant, this is a finding.

Vulnerability Number

V-282768

Documentable

False

Rule Version

TOSS-05-000027

Severity Override Guidance

Sites must document external authenticators being used and that they are NIST compliant.

The following command will verify that Kerberos is functional and produce the list of signing hosts:

$ sudo klist -ekt /etc/krb5.keytab

If external authenticators are being use that are not documented and are not NIST compliant, this is a finding.

Check Content Reference

M

Target Key

5738