GEN000000-LNX00360 - The X server must have the correct options enabled - '-auth'

Information

Without the correct options enabled, the Xwindows system would be less secure and there would be no screen timeout.

Solution

Enable the following options: -audit (at level 4), -auth and -s with 15 minutes as the timeout value.

Procedure for gdm:
Edit /etc/gdm/custom.conf and add the following:
[server-Standard]
name=Standard server
command=/usr/bin/Xorg -br -audit 4 -s 15
chooser=false
handled=true
flexible=true
priority=0

Procedure for xinit:
Edit or create a .xserverrc file in the users home directory containing the startup script for xinit.
This script must have an exec line with at least these options:

exec /usr/bin/X -audit 4 -s 15 -auth <Xauth file> &

The <Xauth file> is created using the 'xauth' command and is customarily located in the users home directory with the name '.Xauthority'.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Group-ID|V-1021, Rule-ID|SV-37207r1_rule, STIG-ID|GEN000000-LNX00360, Vuln-ID|V-1021

Plugin: Unix

Control ID: 7b0d7195f29ed6fc78b2d169148fe04e36d0df71acb78ec9b9712d42018b1eb0