STIGQter STIGQter: STIG Summary: Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide Version: 1 Release: 7 Benchmark Date: 01 Jul 2026:

AlmaLinux OS 9 must limit the number of concurrent sessions to ten for all accounts and/or account types.

DISA Rule

SV-269102r1049984_rule

Vulnerability Number

V-269102

Group Title

SRG-OS-000027-GPOS-00008

Rule Version

ALMA-09-001010

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure AlmaLinux OS 9 to limit the number of concurrent sessions to "10" for all accounts and/or account types.

Add the following line to the top of the /etc/security/limits.conf or in a ".conf" file defined in /etc/security/limits.d/:

* hard maxlogins 10

Check Contents

Verify AlmaLinux OS 9 limits the number of concurrent sessions to "10" for all accounts and/or account types with the following command:

$ grep -rs maxlogins /etc/security/limits.conf /etc/security/limits.d/*.conf

/etc/security/limits.d/maxlogins.conf:* hard maxlogins 10

This can be set as a global domain (with the * wildcard) but may be set differently for multiple domains.

If the "maxlogins" item is missing, commented out, or the value is set greater than 10, this is a finding.

Vulnerability Number

V-269102

Documentable

False

Rule Version

ALMA-09-001010

Severity Override Guidance

Verify AlmaLinux OS 9 limits the number of concurrent sessions to "10" for all accounts and/or account types with the following command:

$ grep -rs maxlogins /etc/security/limits.conf /etc/security/limits.d/*.conf

/etc/security/limits.d/maxlogins.conf:* hard maxlogins 10

This can be set as a global domain (with the * wildcard) but may be set differently for multiple domains.

If the "maxlogins" item is missing, commented out, or the value is set greater than 10, this is a finding.

Check Content Reference

M

Target Key

5664