SOL-11.1-040410 - The system must not allow autologin capabilities from the GNOME desktop.

Information

As automatic logins are a known security risk for other than "kiosk" types of systems, GNOME automatic login should be disabled in pam.conf.

Solution

The root role is required.

Modify the /etc/pam.d/gdm-autologin file.

# pfedit /etc/pam.d/gdm-autologin

Locate the lines:

auth required pam_unix_cred.so.1
auth sufficient pam_allow.so.1
account sufficient pam_allow.so.1

Change the lines to read:

#auth required pam_unix_cred.so.1
#auth sufficient pam_allow.so.1
#account sufficient pam_allow.so.1

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_SPARC_V3R6_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|I, CCI|CCI-000366, Rule-ID|SV-216359r959010_rule, STIG-ID|SOL-11.1-040410, STIG-Legacy|SV-60993, STIG-Legacy|V-48121, Vuln-ID|V-216359

Plugin: Unix

Control ID: 62e7b15b49f6f273052cf9bde61e8803e9c73a3d9c7f2838c231788a95760e2e