SV-204632r603261_rule
V-204632
SRG-OS-000375-GPOS-00160
RHEL-07-041002
CAT II
10
Configure the operating system to implement multifactor authentication for remote access to privileged accounts via pluggable authentication modules (PAM).
Modify all of the services lines in "/etc/sssd/sssd.conf" or in configuration files found under "/etc/sssd/conf.d" to include pam.
Verify the operating system implements multifactor authentication for remote access to privileged accounts via pluggable authentication modules (PAM).
Check the "/etc/sssd/sssd.conf" file for the authentication services that are being used with the following command:
# grep services /etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf
services = nss, pam
If the "pam" service is not present on all "services" lines, this is a finding.
V-204632
False
RHEL-07-041002
Verify the operating system implements multifactor authentication for remote access to privileged accounts via pluggable authentication modules (PAM).
Check the "/etc/sssd/sssd.conf" file for the authentication services that are being used with the following command:
# grep services /etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf
services = nss, pam
If the "pam" service is not present on all "services" lines, this is a finding.
M
2899