SV-215438r508663_rule
V-215438
SRG-OS-000480-GPOS-00227
AIX7-00-003202
CAT II
10
Add or update the following lines in the /etc/pam.conf file:
sshd auth required pam_ckfile
sshd auth required pam_permission file=/etc/security/access.conffound=allow
sshd auth required pam_pmfa /etc/security/pmfa/pam_pmfa.conf
Verify SSH is configured to use multi factor authentication:
# grep ^sshd /etc/pam.conf | head -3
sshd auth required pam_ckfile
sshd auth required pam_permission file=/etc/security/access.conf found=allow
sshd auth required pam_pmfa /etc/security/pmfa/pam_pmfa.conf
If the output does not match the above lines, any lines are missing, or commented out, this is a finding.
V-215438
False
AIX7-00-003202
Verify SSH is configured to use multi factor authentication:
# grep ^sshd /etc/pam.conf | head -3
sshd auth required pam_ckfile
sshd auth required pam_permission file=/etc/security/access.conf found=allow
sshd auth required pam_pmfa /etc/security/pmfa/pam_pmfa.conf
If the output does not match the above lines, any lines are missing, or commented out, this is a finding.
M
4012