SLES-12-010380 - The SUSE operating system must not allow unattended or automatic logon via the graphical user interface.

Information

Failure to restrict system access to authenticated users negatively impacts SUSE operating system security.

Solution

Note: If a graphical user interface is not installed, this requirement is Not Applicable.

Configure the SUSE operating system graphical user interface to not allow unattended or automatic logon to the system.

Add or edit the following lines in the '/etc/sysconfig/displaymanager' configuration file:

DISPLAYMANAGER_AUTOLOGIN=''
DISPLAYMANAGER_PASSWORD_LESS_LOGIN='no'

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SLES_12_V2R13_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|I, CCI|CCI-000366, Rule-ID|SV-217139r877377_rule, STIG-ID|SLES-12-010380, STIG-Legacy|SV-91829, STIG-Legacy|V-77133, Vuln-ID|V-217139

Plugin: Unix

Control ID: 4c465cecb8f27384555fb95251d2d1f6d95b184691fbf9ebd7da58f57d37aecb