SOL-11.1-040170 - The system must require users to re-authenticate to unlock a graphical desktop environment.

Information

Allowing access to a graphical environment when the user is not attending the system can allow unauthorized users access to the system.

Solution

The root role is required.

Edit the global screensaver configuration file to ensure 15 minute screen lock.

# pfedit /usr/share/X11/app-defaults/XScreenSaver

Find the timeout control lines and change them to read:

*timeout: 0:15:00
*lockTimeout: 0:00:05
*lock: True

For each user on the system, edit their local $HOME/.xscreensaver file and change the timeout values.

# pfedit $HOME/.xscreensaver

Find the timeout control lines and change them to read:

timeout: 0:15:00
lockTimeout: 0:00:05
lock: True

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_x86_V3R1_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11b., CAT|II, CCI|CCI-000056, Rule-ID|SV-216101r958400_rule, STIG-ID|SOL-11.1-040170, STIG-Legacy|SV-60917, STIG-Legacy|V-48045, Vuln-ID|V-216101

Plugin: Unix

Control ID: 3d13fa059de481d64e3cf6ff043ceec1d6cbbee31e8dacf8f2105650c0c0aa28