STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 8 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 23 Apr 2021:

RHEL 8 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for graphical user sessions.

DISA Rule

SV-230347r627750_rule

Vulnerability Number

V-230347

Group Title

SRG-OS-000028-GPOS-00009

Rule Version

RHEL-08-020030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the operating system to enable a user's session lock until that user re-establishes access using established identification and authentication procedures.

Create a database to contain the system-wide screensaver settings (if it does not already exist) with the following example:

$ sudo vi /etc/dconf/db/local.d/00-screensaver

Edit the "[org/gnome/desktop/screensaver]" section of the database file and add or update the following lines:

# Set this to true to lock the screen when the screensaver activates
lock-enabled=true

Update the system databases:

$ sudo dconf update

Check Contents

Verify the operating system enables a user's session lock until that user re-establishes access using established identification and authentication procedures with the following command:

$ sudo gsettings get org.gnome.desktop.screensaver lock-enabled

true

If the setting is "false", this is a finding.

Note: This requirement assumes the use of the RHEL 8 default graphical user interface, Gnome Shell. If the system does not have any graphical user interface installed, this requirement is Not Applicable.

Vulnerability Number

V-230347

Documentable

False

Rule Version

RHEL-08-020030

Severity Override Guidance

Verify the operating system enables a user's session lock until that user re-establishes access using established identification and authentication procedures with the following command:

$ sudo gsettings get org.gnome.desktop.screensaver lock-enabled

true

If the setting is "false", this is a finding.

Note: This requirement assumes the use of the RHEL 8 default graphical user interface, Gnome Shell. If the system does not have any graphical user interface installed, this requirement is Not Applicable.

Check Content Reference

M

Target Key

2921

Comments