SV-282372r1201380_rule
V-282372
SRG-OS-000028-GPOS-00009
TOSS-05-000269
CAT II
10
Configure TOSS 5 to enable a user's session lock until that user reestablishes access using established identification and authentication procedures.
Select or create an authselect profile and incorporate the "with-smartcard-lock-on-removal" feature with the following example:
$ sudo authselect select sssd with-smartcard with-smartcard-lock-on-removal
Alternatively, edit the dconf settings in the /etc/dconf/db/* location.
Add or update the [org/gnome/settings-daemon/peripherals/smartcard] section of the /etc/dconf/db/local.d/00-security-settings" database file and add or update the following lines:
[org/gnome/settings-daemon/peripherals/smartcard]
removal-action='lock-screen'
Update the dconf system databases:
$ sudo dconf update
Verify TOSS 5 enables a user's session lock until that user reestablishes access using established identification and authentication procedures using the following command:
Note: This requirement assumes the use of the TOSS 5 default graphical user interface—the GNOME desktop environment. If the system does not have a graphical user interface installed, this requirement is not applicable.
$ grep -R removal-action /etc/dconf/db/*
/etc/dconf/db/distro.d/20-authselect:removal-action='lock-screen'
If the "removal-action='lock-screen'" setting is missing or commented out from the dconf database files, and is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.
V-282372
False
TOSS-05-000269
Verify TOSS 5 enables a user's session lock until that user reestablishes access using established identification and authentication procedures using the following command:
Note: This requirement assumes the use of the TOSS 5 default graphical user interface—the GNOME desktop environment. If the system does not have a graphical user interface installed, this requirement is not applicable.
$ grep -R removal-action /etc/dconf/db/*
/etc/dconf/db/distro.d/20-authselect:removal-action='lock-screen'
If the "removal-action='lock-screen'" setting is missing or commented out from the dconf database files, and is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.
M
5738