SV-258019r1045092_rule
V-258019
SRG-OS-000028-GPOS-00009
RHEL-09-271045
CAT II
10
Configure RHEL 9 to enable a user's session lock until that user re-establishes access using established identification and authentication procedures.
Select or create an authselect profile and incorporate the "with-smartcard-lock-on-removal" feature with the following example:
$ sudo authselect select sssd with-smartcard with-smartcard-lock-on-removal
Alternatively, the dconf settings can be edited in the /etc/dconf/db/* location.
Add or update the [org/gnome/settings-daemon/peripherals/smartcard] section of the /etc/dconf/db/local.d/00-security-settings" database file and add or update the following lines:
[org/gnome/settings-daemon/peripherals/smartcard]
removal-action='lock-screen'
Then update the dconf system databases:
$ sudo dconf update
Note: This requirement assumes the use of the RHEL 9 default graphical user interface, the GNOME desktop environment. If the system does not have any graphical user interface installed, this requirement is Not Applicable.
Verify RHEL 9 enables a user's session lock until that user reestablishes access using established identification and authentication procedures with the following command:
$ gsettings get org.gnome.settings-daemon.peripherals.smartcard removal-action
'lock-screen'
If the result is not 'lock-screen', this is a finding.
V-258019
False
RHEL-09-271045
Note: This requirement assumes the use of the RHEL 9 default graphical user interface, the GNOME desktop environment. If the system does not have any graphical user interface installed, this requirement is Not Applicable.
Verify RHEL 9 enables a user's session lock until that user reestablishes access using established identification and authentication procedures with the following command:
$ gsettings get org.gnome.settings-daemon.peripherals.smartcard removal-action
'lock-screen'
If the result is not 'lock-screen', this is a finding.
M
5551