ALMA-09-001230 - AlmaLinux OS 9 must conceal, via the session lock, information previously visible on the display with a publicly viewable image.

Information

Setting the screensaver mode to blank-only conceals the contents of the display from passersby.

Solution

Configure AlmaLinux OS 9 to prevent a user from overriding the picture-uri setting for graphical user interfaces.

First, in the file "/etc/dconf/db/local.d/00-security-settings" add or update the following lines:

[org/gnome/desktop/screensaver]
picture-uri=''

Then, prevent user modification by adding the following line to "/etc/dconf/db/local.d/locks/00-security-settings-lock":

/org/gnome/desktop/screensaver/picture-uri

Update the dconf system databases:

$ dconf update

See Also

https://workbench.cisecurity.org/benchmarks/0

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11(1), CAT|II, CCI|CCI-000060, Rule-ID|SV-269104r1049986_rule, STIG-ID|ALMA-09-001230, Vuln-ID|V-269104

Plugin: Unix

Control ID: aaf26b4d87ad47447b05e3f471d4904de4dacf5ac4123067b86353f03dd07e2c