UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The macOS system must map the authenticated identity to the user or group account for PKI-based authentication.


Overview

Finding ID Version Rule ID IA Controls Severity
V-95961 AOSX-14-003005 SV-105099r1_rule Medium
Description
Without mapping the certificate used to authenticate to the user account, the ability to determine the identity of the individual user or group will not be available for forensic analysis.
STIG Date
Apple OS X 10.14 (Mojave) Security Technical Implementation Guide 2020-05-29

Details

Check Text ( C-94793r1_chk )
To view the setting for the smartcard certification configuration, run the following command:

sudo /usr/sbin/system_profiler SPConfigurationProfileDataType | /usr/bin/grep enforceSmartCard

If the return is not "enforceSmartCard = 1;" this is a finding.
Fix Text (F-101629r1_fix)
For stand-alone systems, this setting is enforced using the "Smart Card Policy" configuration profile.

Note: Before applying the "Smart Card Policy", the supplemental guidance provided with the STIG should be consulted to ensure continued access to the operating system.