OL09-00-002106 - OL 9 must conceal, via the session lock, information previously visible on the display with a publicly viewable image.

Information

Setting the screensaver mode to blank-only conceals the contents of the display from passersby.

Solution

Configure OL 9 to conceal, via the session lock, information previously visible on the display with a publicly viewable image.

The dconf settings can be edited in the /etc/dconf/db/* location.

Add or update the [org/gnome/desktop/screensaver] section of the "/etc/dconf/db/local.d/00-security-settings" database file and add or update the following lines:

[org/gnome/desktop/screensaver]
picture-uri=''

Add the following line to "/etc/dconf/db/local.d/locks/00-security-settings-lock" to prevent user modification:

/org/gnome/desktop/screensaver/picture-uri

Update the dconf system databases:

$ sudo dconf update

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_9_V1R2_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11(1), CAT|II, CCI|CCI-000060, Rule-ID|SV-271676r1091740_rule, STIG-ID|OL09-00-002106, Vuln-ID|V-271676

Plugin: Unix

Control ID: 910723143cce7d91dc1c049c73569d84083d1325d56a93eaf623e31a0887016b