STIGUI
V-282444CAT II — Medium severitySV-282444r1200312_rule

TOSS 5 must map the authenticated identity to the user or group account for PKI-based authentication.

Rule version TOSS-05-000367 · STIG v1 · 2026-08-20

Discussion

Without mapping the certificate used to authenticate to the user account, the ability to determine the identity of the individual user or group will not be available for forensic analysis.

Check

Verify the certificate of the user or group is mapped to the corresponding user or group in the "sssd.conf" file using the following command:

$ sudo cat /etc/sssd/sssd.conf 

[certmap/testing.test/rule_name] matchrule =<SAN>.*EDIPI@mil maprule = (userCertificate;binary={cert!bin}) domains = testing.test

If the certmap section does not exist, ask the system administrator (SA) to indicate how certificates are mapped to accounts. If there is no evidence of certificate mapping, this is a finding.

Fix

Configure TOSS 5 to map the authenticated identity to the user or group account by adding or modifying the certmap section of the "/etc/sssd/sssd.conf" file based on the following example:

[certmap/testing.test/rule_name] matchrule = .*EDIPI@mil maprule = (userCertificate;binary={cert!bin}) dmains = testing.test

Restart the "sssd" service for the changes to take effect. To restart the "sssd" service, run the following command:

$ sudo systemctl restart sssd.service

Identifiers

Group ID
V-282444
Group title
SRG-OS-000068-GPOS-00036
Rule ID
SV-282444r1200312_rule
Check ID
C-87005r1200310_chk
Fix ID
F-86910r1200311_fix