OL08-00-020035 - OL 8 must terminate idle user sessions.

Information

Terminating an idle session within a short time period reduces the window of opportunity for unauthorized personnel to take control of a management session enabled on the console or console port that has been left unattended.

Solution

Configure OL 8 to log out idle sessions.

Create the directory if necessary:

$ mkdir -p /etc/systemd/logind.conf.d/

Create a *.conf file in /etc/systemd/logind.conf.d/ with the following content:

[Login]
StopIdleSessionSec=600
KillUserProcesses=no

Restart systemd-logind:

$ systemctl restart systemd-logind

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_8_V2R7_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-10, CAT|II, CCI|CCI-001133, Rule-ID|SV-257259r1156674_rule, STIG-ID|OL08-00-020035, Vuln-ID|V-257259

Plugin: Unix

Control ID: fe2647b700a56031ff1883088f03d5c8b92f4591514c2fdc9d0e75fccfdc0441