Skip to content

Install Smart Card Packages For Multifactor Authentication

An XCCDF Rule

Description

Configure the operating system to implement multifactor authentication by installing the required package with the following command: The libpam-pkcs11 package can be installed with the following command:

$ apt-get install libpam-pkcs11

Rationale

Using an authentication device, such as a CAC or token that is separate from the information system, ensures that even if the information system is compromised, that compromise will not affect credentials stored on the authentication device.

Multifactor solutions that require devices separate from information systems gaining access include, for example, hardware tokens providing time-based or challenge-response authenticators and smart cards such as the U.S. Government Personal Identity Verification card and the DoD Common Access Card.

ID
xccdf_org.ssgproject.content_rule_install_smartcard_packages
Severity
Medium
References
Updated



Remediation - OS Build Blueprint


[[packages]]
name = "libpam-pkcs11"
version = "*"

Remediation - Puppet

include install_libpam-pkcs11

class install_libpam-pkcs11 {
  package { 'libpam-pkcs11':
    ensure => 'installed',
  }

Remediation - Ansible

- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-UBTU-20-010063
  - NIST-800-53-CM-6(a)

Remediation - Shell Script

# Remediation is applicable only in certain platforms
if dpkg-query --show --showformat='${db:Status-Status}
' 'kernel' 2>/dev/null | grep -q installed && { ! grep -q s390x /proc/sys/kernel/osrelease; }; then

DEBIAN_FRONTEND=noninteractive apt-get install -y "libpam-pkcs11"