3.17 Only enable GUI login if absolutely necessary - Ensure file /etc/rc2.d/S99dtlogin does NOT exist (Solaris 2.6 or later)


This check only applies to Solaris systems 2.6 or later. Note that for the Solaris CDE GUI to function properly, it is also necessary to enable the rpcbind process (see Item 3.11) and the rpc.ttdbserverd process (see Item 2.8). The X Windows-based CDE GUI on Solaris systems, as well as the rpcbind and rpc.ttdbserverd processes have had a history of security issues. Never run any GUI-oriented service or application on a system unless that machine is protected by a strong network security infrastructure.

See Also


Item Details

Audit Name: CIS Solaris 9 v1.3


References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: 0b1bb066f9ba7f852754a219bd7000df22fca16f5671667d7260df7b3649614c