2.2 Disable Local-only Graphical Login Environment

Information

The graphical login service provides the capability of logging into the system using an X-windows type interface from the console. If graphical login access for the console is required, leave the service in local-only mode.

Rationale:

This service should be disabled if it is not required.

Solution

To disable this service, run the following command:

# svcadm disable svc:/application/graphical-login/gdm:default

See Also

https://workbench.cisecurity.org/benchmarks/4777

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2

Plugin: Unix

Control ID: 144d54bc8043929b01b5e62ac37882297e7c0751ee29085a55985ccc37fcde3a