SV-271684r1091764_rule
V-271684
SRG-OS-000028-GPOS-00009
OL09-00-002126
CAT II
10
Configure OL 9 must prevent a user from overriding the disabling of the graphical user smart card removal action.
Add the following line to "/etc/dconf/db/local.d/locks/00-security-settings-lock":
/org/gnome/settings-daemon/peripherals/smartcard/removal-action
Update the dconf system databases:
$ sudo dconf update
This requirement assumes the use of the OL 9 default graphical user interface—the GNOME desktop environment. If the system does not have any graphical user interface installed, this requirement is Not Applicable.
Verify that OL 9 disables ability of the user to override the smart card removal action setting.
Determine which profile the system database is using with the following command:
$ grep system-db /etc/dconf/profile/user
system-db:local
Check that the removal action setting is locked from nonprivileged user modification with the following command:
Note: The example below is using the database "local" for the system, so the path is "/etc/dconf/db/local.d". This path must be modified if a database other than "local" is being used.
$ grep 'removal-action' /etc/dconf/db/local.d/locks/*
/org/gnome/settings-daemon/peripherals/smartcard/removal-action
If the command does not return at least the example result, this is a finding.
V-271684
False
OL09-00-002126
This requirement assumes the use of the OL 9 default graphical user interface—the GNOME desktop environment. If the system does not have any graphical user interface installed, this requirement is Not Applicable.
Verify that OL 9 disables ability of the user to override the smart card removal action setting.
Determine which profile the system database is using with the following command:
$ grep system-db /etc/dconf/profile/user
system-db:local
Check that the removal action setting is locked from nonprivileged user modification with the following command:
Note: The example below is using the database "local" for the system, so the path is "/etc/dconf/db/local.d". This path must be modified if a database other than "local" is being used.
$ grep 'removal-action' /etc/dconf/db/local.d/locks/*
/org/gnome/settings-daemon/peripherals/smartcard/removal-action
If the command does not return at least the example result, this is a finding.
M
5680