RHEL-09-611160 - RHEL 9 must use the CAC smart card driver.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Smart card login provides two-factor authentication stronger than that provided by a username and password combination. Smart cards leverage public key infrastructure to provide and verify credentials. Configuring the smart card driver in use by the organization helps to prevent users from using unauthorized smart cards.

Satisfies: SRG-OS-000104-GPOS-00051, SRG-OS-000106-GPOS-00053, SRG-OS-000107-GPOS-00054, SRG-OS-000109-GPOS-00056, SRG-OS-000108-GPOS-00055, SRG-OS-000112-GPOS-00057, SRG-OS-000113-GPOS-00058

Solution

Configure RHEL 9 to load the CAC driver.

Add or modify the following line in the '/etc/opensc.conf' file:

card_drivers = cac;

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/U_RHEL_9_V1R1_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000764, CCI|CCI-000766, CCI|CCI-000767, CCI|CCI-000768, CCI|CCI-000770, CCI|CCI-001941, CCI|CCI-001942, Rule-ID|SV-258121r926350_rule, STIG-ID|RHEL-09-611160, Vuln-ID|V-258121

Plugin: Unix

Control ID: b60ece77ccaf13bac0e65552fdd3e12739f19d2b0b59cb740f929fe55129b4ad