SV-269109r1049991_rule
V-269109
SRG-OS-000028-GPOS-00009
ALMA-09-002000
CAT II
10
Configure AlmaLinux OS 9 to enable a user's session lock until that user re-establishes access using established identification and authentication procedures.
Select or create an authselect profile and incorporate the "with-smartcard-lock-on-removal" feature with the following example:
$ authselect select sssd with-smartcard with-smartcard-lock-on-removal
Alternatively, the dconf settings can be edited in the /etc/dconf/db/* location.
Add or update the [org/gnome/settings-daemon/peripherals/smartcard] section of the /etc/dconf/db/local.d/00-security-settings" database file and add or update the following lines:
[org/gnome/settings-daemon/peripherals/smartcard]
removal-action='lock-screen'
Then update the dconf system databases:
$ dconf update
Note: This requirement assumes the use of the AlmaLinux OS 9 default graphical user interface, the GNOME desktop environment. If the system does not have any graphical user interface installed, this requirement is Not Applicable.
Verify AlmaLinux OS 9 enables a user's session lock until that user re-establishes access using established identification and authentication procedures with the following command:
$ grep -R removal-action= /etc/dconf/db/*
/etc/dconf/db/distro.d/00-security-settings:removal-action='lock-screen'
If the "removal-action='lock-screen'" setting is missing or commented out from the dconf database files, this is a finding.
V-269109
False
ALMA-09-002000
Note: This requirement assumes the use of the AlmaLinux OS 9 default graphical user interface, the GNOME desktop environment. If the system does not have any graphical user interface installed, this requirement is Not Applicable.
Verify AlmaLinux OS 9 enables a user's session lock until that user re-establishes access using established identification and authentication procedures with the following command:
$ grep -R removal-action= /etc/dconf/db/*
/etc/dconf/db/distro.d/00-security-settings:removal-action='lock-screen'
If the "removal-action='lock-screen'" setting is missing or commented out from the dconf database files, this is a finding.
M
5664