RHEL-10-200611 - RHEL 10 must have the "pcscd" service set to active.

Information

The information system ensures that even if it is compromised, that compromise will not affect credentials stored on the authentication device.

The daemon program for "pcsc-lite" and the MuscleCard framework is "pcscd". It is a resource manager that coordinates communications with smart card readers, smart cards, and cryptographic tokens that are connected to the system.

Solution

Configure RHEL 10 to have the "pcscd" socket set to active with the following command:

$ sudo systemctl enable --now pcscd.socket

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_10_V1R1_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2(6), CAT|II, CCI|CCI-004046, Rule-ID|SV-280973r1165274_rule, STIG-ID|RHEL-10-200611, Vuln-ID|V-280973

Plugin: Unix

Control ID: f3fbb2b747cb3006c07ac5455984b89ac0878fc6c7d2247dc7262bb909406661