Amazon Linux 2023 must have the opensc package installed.

STIG ID: AZLX-23-001125  |  SRG: SRG-OS-000375-GPOS-00160 |  Severity: medium (CAT II)  |  CCI: CCI-004046,CCI-001953 |  Vulnerability Id: V-274036

Vulnerability Discussion

The use of PIV credentials facilitates standardization and reduces the risk of unauthorized access.

The DOD has mandated the use of the Common Access Card (CAC) to support identity management and personal authentication for systems covered under Homeland Security Presidential Directive (HSPD) 12, as well as making the CAC a primary component of layered protection for national security systems.

Satisfies: SRG-OS-000375-GPOS-00160, SRG-OS-000376-GPOS-00161

Check

Verify Amazon Linux 2023 has the opensc package installed with the following command:

$ sudo dnf list --installed opensc
Installed Packages
opensc.x86_64 0.24.0-1.amzn2023.0.4 @amazonlinux

If the "opensc" package is not installed, this is a finding.

Fix

Configure Amazon Linux 2023 to have the opensc package installed with the following command:

$ sudo dnf install -y opensc