OL6-00-000527 - The login user list must be disabled.

Information

Leaving the user list enabled is a security risk since it allows anyone with physical access to the system to quickly enumerate known user accounts without logging in.

Solution

In the default graphical environment, users logging directly into the system are greeted with a login screen that displays all known users. This functionality should be disabled.

Run the following command to disable the user list:

$ sudo gconftool-2 --direct
--config-source xml:readwrite:/etc/gconf/gconf.xml.mandatory
--type bool --set /apps/gdm/simple-greeter/disable_user_list true

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_6_V2R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-209070r793791_rule, STIG-ID|OL6-00-000527, STIG-Legacy|SV-73807, STIG-Legacy|V-59377, Vuln-ID|V-209070

Plugin: Unix

Control ID: 2f953351721f9327b34e88d6df65aeb62112dd5269739a6cce99bbd7b486344c