RHEL-09-271040 - RHEL 9 must not allow unattended or automatic logon via the graphical user interface.

Information

Failure to restrict system access to authenticated users negatively impacts operating system security.

Solution

Configure the GNOME desktop display manager to disable automatic login.

Set AutomaticLoginEnable to false in the [daemon] section in /etc/gdm/custom.conf. For example:

[daemon]
AutomaticLoginEnable=false

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_9_V2R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|I, CCI|CCI-000366, Rule-ID|SV-258018r991591_rule, STIG-ID|RHEL-09-271040, Vuln-ID|V-258018

Plugin: Unix

Control ID: a133566b65856191dea3ebc768a3792daf3d2930f3a111d755e268ba6287a634