SV-217299r603262_rule
V-217299
SRG-OS-000375-GPOS-00160
SLES-12-030500
CAT II
10
Configure the SUSE operating system to implement multifactor authentication by installing the required packages.
Install the packages required to support multifactor authentication with the following commands:
#zypper install pam_pkcs11
#zypper install mozilla-nss
#zypper install mozilla-nss-tools
#zypper install pcsc-ccid
#zypper install pcsc-lite
#zypper install pcsc-tools
#zypper install opensc
#zypper install coolkey
Additional information on the configuration of multifactor authentication on the SUSE operating system can be found at https://www.suse.com/communities/blog/configuring-smart-card-authentication-suse-linux-enterprise/
Verify the SUSE operating system has the packages required for multifactor authentication installed.
Check for the presence of the packages required to support multifactor authentication with the following commands:
# zypper se pam_pkcs11
i | pam_pkcs11 | PKCS #11 PAM Module | package
# zypper se mozilla-nss
i | mozilla-nss | Network Security Services | package
i | mozilla-nss-tools | Tools for developing, debugging, and managing applications t-> | package
# zypper se pcsc
i | pcsc-ccid | PCSC Driver for CCID Based Smart Card Readers and GemPC Twin -> | package
i | pcsc-lite | PCSC Smart Cards Library | package
i | pcsc-tools | PCSC Tools | package
# zypper se opensc
i | opensc | Smart Card Utilities | package
# zypper info coolkey | grep -i installed
Installed: Yes
If any of the packages required for multifactor authentication are not installed, this is a finding.
V-217299
False
SLES-12-030500
Verify the SUSE operating system has the packages required for multifactor authentication installed.
Check for the presence of the packages required to support multifactor authentication with the following commands:
# zypper se pam_pkcs11
i | pam_pkcs11 | PKCS #11 PAM Module | package
# zypper se mozilla-nss
i | mozilla-nss | Network Security Services | package
i | mozilla-nss-tools | Tools for developing, debugging, and managing applications t-> | package
# zypper se pcsc
i | pcsc-ccid | PCSC Driver for CCID Based Smart Card Readers and GemPC Twin -> | package
i | pcsc-lite | PCSC Smart Cards Library | package
i | pcsc-tools | PCSC Tools | package
# zypper se opensc
i | opensc | Smart Card Utilities | package
# zypper info coolkey | grep -i installed
Installed: Yes
If any of the packages required for multifactor authentication are not installed, this is a finding.
M
4033