STIGUI
V-285222CAT II — Medium severitySV-285222r1264151_rule

The Photon operating system must be configured to use the pam_deny.so module.

Rule version PHTN-40-000267 · STIG v2 · 2026-08-26

Discussion

Configuring the operating system to implement organizationwide security implementation guides and security checklists ensures compliance with federal standards and establishes a common security baseline across DoW that reflects the most restrictive security posture consistent with operational requirements.

Configuration settings are the set of parameters that can be changed in hardware, software, or firmware components of the system that affect the security posture and/or functionality of the system. Security-related parameters impact the security state of the system and include the parameters required to satisfy other security control requirements. Security-related parameters include, for example, registry settings; account, file, and directory permission settings; and settings for functions, ports, protocols, services, and remote connections.

Check

At the command line, run the following commands to verify the pam_deny.so module is used:

# grep '^auth' /etc/pam.d/system-auth

Example result:

auth required pam_faillock.so preauth auth sufficient pam_unix.so auth required pam_faillock.so authfail auth optional pam_faildelay.so delay=4000000 auth required pam_deny.so

If the pam_deny.so module is not present, or is not configured as the last auth entry, this is a finding.

Fix

Navigate to and open:

/etc/pam.d/system-auth

Add or update the following line making sure it is present as the last auth entry:

auth required pam_deny.so

Identifiers

Group ID
V-285222
Group title
SRG-OS-000480-GPOS-00228
Rule ID
SV-285222r1264151_rule
Check ID
C-89791r1210424_chk
Fix ID
F-89696r1264150_fix