SV-221659r603260_rule
V-221659
SRG-OS-000029-GPOS-00010
OL07-00-010062
CAT II
10
Configure the operating system to prevent a user from overriding a screensaver lock after a 15-minute period of inactivity for graphical user interfaces.
Create a database to contain the system-wide screensaver settings (if it does not already exist) with the following command:
Note: The example below is using the database "local" for the system, so if the system is using another database in "/etc/dconf/profile/user", the file should be created under the appropriate subdirectory.
# touch /etc/dconf/db/local.d/locks/session
Add the setting to lock the screensaver lock-enabled setting:
/org/gnome/desktop/screensaver/lock-enabled
Verify the operating system prevents a user from overriding the screensaver lock-enabled setting for the graphical user interface.
Note: If the system does not have GNOME installed, this requirement is Not Applicable. The screen program must be installed to lock sessions on the console.
Determine which profile the system database is using with the following command:
# grep system-db /etc/dconf/profile/user
system-db:local
Check for the lock-enabled setting with the following command:
Note: The example below is using the database "local" for the system, so the path is "/etc/dconf/db/local.d". This path must be modified if a database other than "local" is being used.
# grep -i lock-enabled /etc/dconf/db/local.d/locks/*
/org/gnome/desktop/screensaver/lock-enabled
If the command does not return a result, this is a finding.
V-221659
False
OL07-00-010062
Verify the operating system prevents a user from overriding the screensaver lock-enabled setting for the graphical user interface.
Note: If the system does not have GNOME installed, this requirement is Not Applicable. The screen program must be installed to lock sessions on the console.
Determine which profile the system database is using with the following command:
# grep system-db /etc/dconf/profile/user
system-db:local
Check for the lock-enabled setting with the following command:
Note: The example below is using the database "local" for the system, so the path is "/etc/dconf/db/local.d". This path must be modified if a database other than "local" is being used.
# grep -i lock-enabled /etc/dconf/db/local.d/locks/*
/org/gnome/desktop/screensaver/lock-enabled
If the command does not return a result, this is a finding.
M
4089