STIGhub
STIGs
RMF Controls
Compare
← IA-2 (12) — Identification and Authentication (Organizational Users)
CCI-001954
Definition
Electronically verify Personal Identity Verification-compliant credentials.
Parent Control
IA-2 (12)
Identification and Authentication (Organizational Users)
Identification and Authentication
Linked STIG Checks (71)
V-279055
CAT I
ColdFusion must be using an enterprise solution for authentication.
Adobe ColdFusion Security Technical Implementation Guide
V-274037
CAT II
Amazon Linux 2023 must have the openssl-pkcs11 package installed.
Amazon Linux 2023 Security Technical Implementation Guide
V-274061
CAT II
Amazon Linux 2023 must implement certificate status checking for multifactor authentication.
Amazon Linux 2023 Security Technical Implementation Guide
V-268177
CAT II
NixOS must implement multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.
Anduril NixOS Security Technical Implementation Guide
V-222993
CAT II
Multifactor certificate-based tokens (CAC) must be used when accessing the management interface.
Apache Tomcat Application Server 9 Security Technical Implementation Guide
V-252477
CAT II
The macOS system must accept and verify Personal Identity Verification (PIV) credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions.
Apple macOS 12 (Monterey) Security Technical Implementation Guide
V-257183
CAT II
The macOS system must accept and verify Personal Identity Verification (PIV) credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DOD PKI-established certificate authorities for verification of the establishment of protected sessions.
Apple macOS 13 (Ventura) Security Technical Implementation Guide
V-268471
CAT II
The macOS system must set smart card certificate trust to moderate.
Apple macOS 15 (Sequoia) Security Technical Implementation Guide
V-277078
CAT II
The macOS system must set smart card certificate trust to moderate.
Apple macOS 26 (Tahoe) Security Technical Implementation Guide
V-222525
CAT II
The application must electronically verify Personal Identity Verification (PIV) credentials.
Application Security and Development Security Technical Implementation Guide
V-204801
CAT I
The application server must electronically verify Personal Identity Verification (PIV) credentials for access to the management interface.
Application Server Security Requirements Guide
V-237336
CAT II
The ArcGIS Server must accept and electronically verify Personal Identity Verification (PIV) credentials.
ArcGIS for Server 10.3 Security Technical Implementation Guide
V-272639
CAT II
CylanceON-PREM must be configured with a DOD issued certificate (or another authorizing official [AO]-approved certificate).
Arctic Wolf CylanceON-PREM Security Technical Implementation Guide
V-256844
CAT I
Compliance Guardian must use multifactor authentication for network access to privileged accounts.
AvePoint Compliance Guardian Security Technical Implementation Guide
V-276012
CAT I
Ax-OS must have no local accounts for the user interface.
Axonius Federal Systems Ax-OS Security Technical Implementation Guide
V-219317
CAT II
The Ubuntu operating system must implement smart card logins for multifactor authentication for access to accounts.
Canonical Ubuntu 18.04 LTS Security Technical Implementation Guide
V-219320
CAT II
The Ubuntu operating system must implement certificate status checking for multifactor authentication.
Canonical Ubuntu 18.04 LTS Security Technical Implementation Guide
V-238232
CAT II
The Ubuntu operating system must electronically verify Personal Identity Verification (PIV) credentials.
Canonical Ubuntu 20.04 LTS Security Technical Implementation Guide
V-260576
CAT II
Ubuntu 22.04 LTS must electronically verify personal identity verification (PIV) credentials.
Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide
V-270723
CAT II
Ubuntu 24.04 LTS must electronically verify Personal Identity Verification (PIV) credentials.
Canonical Ubuntu 24.04 LTS Security Technical Implementation Guide
V-206507
CAT II
The Central Log Server must be configured to electronically verify the DoD CAC credential.
Central Log Server Security Requirements Guide
V-234252
CAT II
Citrix StoreFront server must accept Personal Identity Verification (PIV) credentials.
Citrix Virtual Apps and Desktop 7.x StoreFront Security Technical Implementation Guide
V-234262
CAT II
Citrix Workspace must accept Personal Identity Verification (PIV) credentials.
Citrix Virtual Apps and Desktop 7.x Workspace App Security Technical Implementation Guide
V-213209
CAT II
Citrix Receiver must accept Personal Identity Verification (PIV) credentials.
Citrix XenDesktop 7.x Receiver Security Technical Implementation Guide
V-213211
CAT II
XenDesktop StoreFront must accept Personal Identity Verification (PIV) credentials.
Citrix XenDesktop 7.x StoreFront Security Technical Implementation Guide
V-259875
CAT II
The cloud service offering (CSO) must be configured to use DOD public key infrastructure (PKI) to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
Cloud Computing Mission Owner Operating System Security Requirements Guide
V-269373
CAT II
AlmaLinux OS 9 must have the openssl-pkcs11 package installed.
Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide
V-235780
CAT II
LDAP integration in Docker Enterprise must be configured.
Docker Enterprise 2.x Linux/UNIX Security Technical Implementation Guide
V-235821
CAT II
SAML integration must be enabled in Docker Enterprise.
Docker Enterprise 2.x Linux/UNIX Security Technical Implementation Guide
V-271034
CAT II
Dragos Platform must accept the DOD CAC or other PKI credential for identity management and personal authentication.
Dragos Platform 2.x Security Technical Implementation Guide
V-278400
CAT II
NGINX must accept Personal Identity Verification (PIV) credentials.
F5 NGINX Security Technical Implementation Guide
V-203729
CAT II
The operating system must electronically verify Personal Identity Verification (PIV) credentials.
General Purpose Operating System Security Requirements Guide
V-215441
CAT II
The AIX operating system must accept and verify Personal Identity Verification (PIV) credentials.
IBM AIX 7.x Security Technical Implementation Guide
V-255763
CAT II
WebGUI access to the MQ Appliance network device must electronically verify Personal Identity Verification (PIV) credentials.
IBM MQ Appliance v9.0 NDM Security Technical Implementation Guide
V-255865
CAT II
The WebSphere Application Server multifactor authentication for network access to privileged accounts must be used.
IBM WebSphere Traditional V9.x Security Technical Implementation Guide
V-258589
CAT I
The ICS must be configured to use multifactor authentication (e.g., DOD PKI) for network access to nonprivileged accounts.
Ivanti Connect Secure VPN Security Technical Implementation Guide
V-205571
CAT II
The Mainframe Product must electronically verify Personal Identity Verification (PIV) credentials.
Mainframe Product Security Requirements Guide
V-223042
CAT II
Prevent ignoring certificate errors option must be enabled.
Microsoft Internet Explorer 11 Security Technical Implementation Guide
V-254111
CAT II
Nutanix AOS must accept Personal Identity Verification (PIV) credentials to access the management interface.
Nutanix AOS 5.20.x Application Security Technical Implementation Guide
V-221895
CAT II
The Oracle Linux operating system must have the required packages for multifactor authentication installed.
Oracle Linux 7 Security Technical Implementation Guide
V-221896
CAT II
The Oracle Linux operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
Oracle Linux 7 Security Technical Implementation Guide
V-221897
CAT II
The Oracle Linux operating system must implement certificate status checking for PKI authentication.
Oracle Linux 7 Security Technical Implementation Guide
V-248587
CAT II
OL 8 must implement certificate status checking for multifactor authentication.
Oracle Linux 8 Security Technical Implementation Guide
V-271491
CAT II
OL 9 must have the openssl-pkcs11 package installed.
Oracle Linux 9 Security Technical Implementation Guide
V-271608
CAT II
OL 9 must implement certificate status checking for multifactor authentication (MFA).
Oracle Linux 9 Security Technical Implementation Guide
V-281005
CAT II
RHEL 10 must have the "pkcs11-provider" package installed.
Red Hat Enterprise Linux 10 Security Technical Implementation Guide
V-281325
CAT II
RHEL 10 must implement certificate status checking for multifactor authentication.
Red Hat Enterprise Linux 10 Security Technical Implementation Guide
V-204397
CAT II
The Red Hat Enterprise Linux operating system must uniquely identify and must authenticate users using multifactor authentication via a graphical user logon.
Red Hat Enterprise Linux 7 Security Technical Implementation Guide
V-204631
CAT II
The Red Hat Enterprise Linux operating system must have the required packages for multifactor authentication installed.
Red Hat Enterprise Linux 7 Security Technical Implementation Guide
V-204632
CAT II
The Red Hat Enterprise Linux operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
Red Hat Enterprise Linux 7 Security Technical Implementation Guide
V-204633
CAT II
The Red Hat Enterprise Linux operating system must implement certificate status checking for PKI authentication.
Red Hat Enterprise Linux 7 Security Technical Implementation Guide
V-257838
CAT II
RHEL 9 must have the openssl-pkcs11 package installed.
Red Hat Enterprise Linux 9 Security Technical Implementation Guide
V-258123
CAT II
RHEL 9 must implement certificate status checking for multifactor authentication.
Red Hat Enterprise Linux 9 Security Technical Implementation Guide
V-254093
CAT I
Innoslate must use multifactor authentication for network access to privileged and non-privileged accounts.
SPEC Innovations Innoslate 4.x Security Technical Implementation Guide
V-261396
CAT II
SLEM 5 must have the packages required for multifactor authentication to be installed.
SUSE Linux Enterprise Micro (SLEM) 5 Security Technical Implementation Guide
V-261397
CAT II
SLEM 5 must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
SUSE Linux Enterprise Micro (SLEM) 5 Security Technical Implementation Guide
V-261398
CAT II
SLEM 5 must implement certificate status checking for multifactor authentication.
SUSE Linux Enterprise Micro (SLEM) 5 Security Technical Implementation Guide
V-217299
CAT II
The SUSE operating system must have the packages required for multifactor authentication to be installed.
SUSE Linux Enterprise Server 12 Security Technical Implementation Guide
V-217300
CAT II
The SUSE operating system must implement certificate status checking for multifactor authentication.
SUSE Linux Enterprise Server 12 Security Technical Implementation Guide
V-217301
CAT II
The SUSE operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
SUSE Linux Enterprise Server 12 Security Technical Implementation Guide
V-281377
CAT II
TCMax must accept personal identity verification (PIV) credentials.
Soaring Software Solutions TCMax 9.x Security Technical Implementation Guide
V-241005
CAT II
Common Access Card (CAC)-based authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
Tanium 7.0 Security Technical Implementation Guide
V-234066
CAT II
Common Access Card (CAC)-based authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
Tanium 7.3 Security Technical Implementation Guide
V-254897
CAT II
Multifactor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
Tanium 7.x Application on TanOS Security Technical Implementation Guide
V-253799
CAT II
The Tanium application must electronically verify Personal Identity Verification (PIV) credentials.
Tanium 7.x Security Technical Implementation Guide
V-282592
CAT II
TOSS 5 must have the opensc package installed.
Tri-Lab Operating System Stack (TOSS) 5 Security Technical Implementation Guide
V-256333
CAT II
The vCenter Server must enable revocation checking for certificate-based authentication.
VMware vSphere 7.0 vCenter Security Technical Implementation Guide
V-258919
CAT II
The vCenter Server must enable revocation checking for certificate-based authentication.
VMware vSphere 8.0 vCenter Security Technical Implementation Guide
V-207482
CAT II
The VMM must electronically verify Personal Identity Verification (PIV) credentials.
Virtual Machine Manager Security Requirements Guide
V-207240
CAT II
The VPN Gateway must electronically verify the Common Access Card (CAC) credential.
Virtual Private Network (VPN) Security Requirements Guide
V-269574
CAT I
Xylok Security Suite must use a centralized user management solution.
Xylok Security Suite 20.x Security Technical Implementation Guide