1.8.4 Ensure XDCMP is not enabled

Information

X Display Manager Control Protocol (XDMCP) is designed to provide authenticated access to display management services for remote displays

Rationale:

XDMCP is inherently insecure.

XDMCP is not a ciphered protocol. This may allow an attacker to capture keystrokes entered by a user

XDMCP is vulnerable to man-in-the-middle attacks. This may allow an attacker to steal the credentials of legitimate users by impersonating the XDMCP server.

Solution

Edit the file /etc/gdm/custom.conf and remove the line

Enable=true

Default Value:

false (This is denoted by no Enabled= entry in the file /etc/gdm/custom.conf in the [xdmcp] section

See Also

https://workbench.cisecurity.org/files/3152

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Unix

Control ID: 9ea2e0e9415fc5c0817db62f48ac65e029dc7e6043c06b2e1147c0d87529c822