1.109 SOL-11.1-040410

Information

The system must not allow autologin capabilities from the GNOME desktop.

GROUP ID: V-216359
RULE ID: SV-216359r959010

As automatic logins are a known security risk for other than "kiosk" types of systems, GNOME automatic login should be disabled in pam.conf.

Solution

The root role is required.

Modify the /etc/pam.d/gdm-autologin file.

# pfedit /etc/pam.d/gdm-autologin

Locate the lines:

auth required pam_unix_cred.so.1
auth sufficient pam_allow.so.1
account sufficient pam_allow.so.1

Change the lines to read:

#auth required pam_unix_cred.so.1
#auth sufficient pam_allow.so.1
#account sufficient pam_allow.so.1

See Also

https://workbench.cisecurity.org/benchmarks/23765