RHEL 8, for certificate-based authentication, must enforce authorized access to the corresponding private key.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-230230
RHEL-08-010100
SV-230230r1017049_rule
Medium
Description
If an unauthorized user obtains access to a private key without a passcode, that user would have unauthorized access to any system where the associated public key has been installed.