SV-221665r603260_rule
V-221665
SRG-OS-000029-GPOS-00010
OL07-00-010101
CAT II
10
Configure the operating system to prevent a user from overriding a screensaver lock after a 15-minute period of inactivity for graphical user interfaces.
Create a database to contain the system-wide screensaver settings (if it does not already exist) with the following command:
Note: The example below is using the database "local" for the system, so if the system is using another database in "/etc/dconf/profile/user", the file should be created under the appropriate subdirectory.
# touch /etc/dconf/db/local.d/locks/session
Add the setting to lock the screensaver idle-activation-enabled setting:
/org/gnome/desktop/screensaver/idle-activation-enabled
Verify the operating system prevents a user from overriding the screensaver idle-activation-enabled setting for the graphical user interface.
Note: If the system does not have GNOME installed, this requirement is Not Applicable. The screen program must be installed to lock sessions on the console.
Determine which profile the system database is using with the following command:
# grep system-db /etc/dconf/profile/user
system-db:local
Check for the idle-activation-enabled setting with the following command:
Note: The example below is using the database "local" for the system, so the path is "/etc/dconf/db/local.d". This path must be modified if a database other than "local" is being used.
# grep -i idle-activation-enabled /etc/dconf/db/local.d/locks/*
/org/gnome/desktop/screensaver/idle-activation-enabled
If the command does not return a result, this is a finding.
V-221665
False
OL07-00-010101
Verify the operating system prevents a user from overriding the screensaver idle-activation-enabled setting for the graphical user interface.
Note: If the system does not have GNOME installed, this requirement is Not Applicable. The screen program must be installed to lock sessions on the console.
Determine which profile the system database is using with the following command:
# grep system-db /etc/dconf/profile/user
system-db:local
Check for the idle-activation-enabled setting with the following command:
Note: The example below is using the database "local" for the system, so the path is "/etc/dconf/db/local.d". This path must be modified if a database other than "local" is being used.
# grep -i idle-activation-enabled /etc/dconf/db/local.d/locks/*
/org/gnome/desktop/screensaver/idle-activation-enabled
If the command does not return a result, this is a finding.
M
4089