RHEL-10-701290 - RHEL 10 must prohibit the use of cached authenticators after one day.

Information

If cached authentication information is out of date, the validity of the authentication information may be questionable.

Solution

Configure RHEL 10 SSSD to prohibit the use of cached authentications after one day.

Edit the file "/etc/sssd/sssd.conf" or a configuration file in "/etc/sssd/conf.d" and add or edit the following line just below the line [pam]:

offline_credentials_expiration = 1

Restart the "sssd" service with the following command for the changes to take effect:

$ sudo systemctl restart sssd.service

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_10_V1R1_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(13), CAT|II, CCI|CCI-002007, Rule-ID|SV-281331r1167143_rule, STIG-ID|RHEL-10-701290, Vuln-ID|V-281331

Plugin: Unix

Control ID: 11f34cac6e8d3a97a7ffa7283a6cb0897a2f4ae32814bbc647fb309961fa5778