SV-238232r653871_rule
V-238232
SRG-OS-000377-GPOS-00162
UBTU-20-010065
CAT II
10
Configure the Ubuntu operating system to do certificate status checking for multifactor authentication.
Modify all of the "cert_policy" lines in "/etc/pam_pkcs11/pam_pkcs11.conf" to include "ocsp_on".
Verify the Ubuntu operating system electronically verifies PIV credentials.
Verify that certificate status checking for multifactor authentication is implemented with the following command:
$ sudo grep use_pkcs11_module /etc/pam_pkcs11/pam_pkcs11.conf | awk '/pkcs11_module opensc {/,/}/' /etc/pam_pkcs11/pam_pkcs11.conf | grep cert_policy | grep ocsp_on
cert_policy = ca,signature,ocsp_on;
If "cert_policy" is not set to "ocsp_on", or the line is commented out, this is a finding.
V-238232
False
UBTU-20-010065
Verify the Ubuntu operating system electronically verifies PIV credentials.
Verify that certificate status checking for multifactor authentication is implemented with the following command:
$ sudo grep use_pkcs11_module /etc/pam_pkcs11/pam_pkcs11.conf | awk '/pkcs11_module opensc {/,/}/' /etc/pam_pkcs11/pam_pkcs11.conf | grep cert_policy | grep ocsp_on
cert_policy = ca,signature,ocsp_on;
If "cert_policy" is not set to "ocsp_on", or the line is commented out, this is a finding.
M
5318