SV-221896r603260_rule
V-221896
SRG-OS-000375-GPOS-00160
OL07-00-041002
CAT II
10
Configure the operating system to implement multifactor authentication for remote access to privileged accounts via pluggable authentication modules (PAM).
Modify all of the services lines in "/etc/sssd/sssd.conf" or in configuration files found under "/etc/sssd/conf.d" to include pam.
Verify the operating system implements multifactor authentication for remote access to privileged accounts via pluggable authentication modules (PAM).
Check the "/etc/sssd/sssd.conf" file for the authentication services that are being used with the following command:
# grep services /etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf
services = nss, pam
If the "pam" service is not present on all "services" lines, this is a finding.
V-221896
False
OL07-00-041002
Verify the operating system implements multifactor authentication for remote access to privileged accounts via pluggable authentication modules (PAM).
Check the "/etc/sssd/sssd.conf" file for the authentication services that are being used with the following command:
# grep services /etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf
services = nss, pam
If the "pam" service is not present on all "services" lines, this is a finding.
M
4089