RHEL 10 must have the "opensc" package installed.

STIG ID: RHEL-10-200620  |  SRG: SRG-OS-000375-GPOS-00160 |  Severity: medium (CAT II)  |  CCI: CCI-004046,CCI-001953 |  Vulnerability Id: V-280975

Vulnerability Discussion

The use of Personal Identity Verification (PIV) credentials facilitates standardization and reduces the risk of unauthorized access.

The DOD has mandated the use of the common access card (CAC) to support identity management and personal authentication for systems covered under Homeland Security Presidential Directive (HSPD) 12, as well as making the CAC a primary component of layered protection for national security systems.

Satisfies: SRG-OS-000375-GPOS-00160, SRG-OS-000376-GPOS-00161

Check

Verify RHEL 10 has the "opensc" package installed with the following command:

$ sudo dnf list --installed opensc
Installed Packages
opensc.x86_64 0.26.1-1.el10 @rhel-10-for-x86_64-baseos-rpm

If the "opensc" package is not installed, this is a finding.

Fix

Configure RHEL 10 to have the "opensc" package installed with the following command:

$ sudo dnf -y install opensc