SV-271690r1092634_rule
V-271690
SRG-OS-000028-GPOS-00009
OL09-00-002160
CAT II
10
Configure OL 9 to enable a user's session lock until that user reestablishes access using established identification and authentication procedures.
Select or create an authselect profile and incorporate the "with-smartcard-lock-on-removal" feature with the following example:
$ sudo authselect select sssd with-smartcard with-smartcard-lock-on-removal
Alternatively, the dconf settings can be edited in the /etc/dconf/db/* location.
Add or update the [org/gnome/settings-daemon/peripherals/smartcard] section of the /etc/dconf/db/local.d/00-security-settings" database file and add or update the following lines:
[org/gnome/settings-daemon/peripherals/smartcard]
removal-action='lock-screen'
Update the dconf system databases:
$ sudo dconf update
This requirement assumes the use of the OL 9 default graphical user interface—the GNOME desktop environment. If the system does not have any graphical user interface installed, this requirement is Not Applicable.
Verify that OL 9 enables a user's session lock until that user reestablishes access using established identification and authentication procedures with the following command:
$ grep -R removal-action /etc/dconf/db/*
/etc/dconf/db/distro.d/20-authselect:removal-action='lock-screen'
If the "removal-action='lock-screen'" setting is missing or commented out from the dconf database files, this is a finding.
V-271690
False
OL09-00-002160
This requirement assumes the use of the OL 9 default graphical user interface—the GNOME desktop environment. If the system does not have any graphical user interface installed, this requirement is Not Applicable.
Verify that OL 9 enables a user's session lock until that user reestablishes access using established identification and authentication procedures with the following command:
$ grep -R removal-action /etc/dconf/db/*
/etc/dconf/db/distro.d/20-authselect:removal-action='lock-screen'
If the "removal-action='lock-screen'" setting is missing or commented out from the dconf database files, this is a finding.
M
5680