Check: AZLX-23-001115
Amazon Linux 2023 STIG:
AZLX-23-001115
(in version v1 r1)
Title
Amazon Linux 2023 must have the pcsc-lite package installed. (Cat II impact)
Discussion
The pcsc-lite package must be installed if it is to be available for multifactor authentication using smart cards.
Check Content
Verify Amazon Linux 2023 has the pcsc-lite package installed with the following command: $ dnf list --installed pcsc-lite Installed Packages pcsc-lite.x86_64 1.9.1-1.amzn2023.0.4 @amazonlinux If the "pcsc-lite" package is not installed, this is a finding.
Fix Text
Configure Amazon Linux 2023 to have the pcsc-lite package installed with the following command: $ sudo dnf install -y pcsc-lite
Additional Identifiers
Rule ID: SV-274034r1120090_rule
Vulnerability ID: V-274034
Group Title: SRG-OS-000375-GPOS-00160
Expert Comments
CCIs
| Number | Definition |
|---|---|
| CCI-004046 |
Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access. |
Controls
| Number | Title |
|---|---|
| IA-2(6) |
Access to Accounts —separate Device |