ALMA-09-029720 - AlmaLinux OS 9 must be configured to disable Bluetooth.

Information

This requirement applies to wireless peripheral technologies (e.g., wireless mice, keyboards, displays, etc.) used with AlmaLinux OS 9 systems.

Wireless peripherals (e.g., Wi-Fi/Bluetooth/IR keyboards, mice and pointing devices, and near field communications [NFC]) present a unique challenge by creating an open, unsecured port on a computer. Wireless peripherals must meet DOD requirements for wireless data transmission and be approved for use by the authorizing official (AO). Even though some wireless peripherals, such as mice and pointing devices, do not ordinarily carry information that need to be protected, modification of communications with these wireless peripherals may be used to compromise the AlmaLinux OS 9 operating system.

Solution

To configure the system to prevent the Bluetooth kernel module from being loaded, run the following command:

$ cat << EOF | tee /etc/modprobe.d/bluetooth.conf
install bluetooth /bin/false
blacklist bluetooth
EOF

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CL_AlmaLinux_OS_9_V1R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-269342r1050224_rule, STIG-ID|ALMA-09-029720, Vuln-ID|V-269342

Plugin: Unix

Control ID: 72857c745a03e7d714a75f0fcb366d5b6a80aaf71cb802bffd2c901cb8ecd862