Information
RHEL 10 must enable certificate-based smart card authentication.
GROUP ID: V-281324RULE ID: SV-281324r1167122
Without the use of multifactor authentication, the ease of access to privileged functions is greatly increased. Multifactor authentication requires using two or more factors to achieve authentication. A privileged account is defined as an information system account with authorizations of a privileged user. The DOD Common Access Card (CAC) with DOD-approved public key infrastructure (PKI) is an example of multifactor authentication.
Satisfies: SRG-OS-000375-GPOS-00160, SRG-OS-000105-GPOS-00052, SRG-OS-000106-GPOS-00053, SRG-OS-000107-GPOS-00054, SRG-OS-000108-GPOS-00055
Solution
Configure RHEL 10 to enable certificate-based smart card authentication.
Edit the file "/etc/sssd/sssd.conf" or a configuration file in "/etc/sssd/conf.d" and add or edit the following line:
pam_cert_auth = True