SV-230828r599842_rule
V-230828
SRG-OS-000378-GPOS-00163
APPL-11-002069
CAT II
10
To ensure that authentication is required to access all system level preference panes use the following procedure:
Copy the authorization database to a file using the following command:
/usr/bin/sudo /usr/bin/security authorizationdb read system.preferences > ~/Desktop/authdb.txt
edit the file to change:
<key>shared</key>
<true/>
To read:
<key>shared</key>
<false/>
Reload the authorization database with the following command:
/usr/bin/sudo /usr/bin/security authorizationdb write system.preferences < ~/Desktop/authdb.txt
To check that macOS is configured to require authentication to all system preference panes, use the following commands:
/usr/bin/sudo /usr/bin/security authorizationdb read system.preferences | grep -A1 shared
If what is returned does not include the following, this is a finding.
<key>shared</key>
<false/>
V-230828
False
APPL-11-002069
To check that macOS is configured to require authentication to all system preference panes, use the following commands:
/usr/bin/sudo /usr/bin/security authorizationdb read system.preferences | grep -A1 shared
If what is returned does not include the following, this is a finding.
<key>shared</key>
<false/>
M
5246