UBTU-16-010330 - Unattended or automatic login via the Graphical User Interface must not be allowed - autologin-user

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Failure to restrict system access to authenticated users negatively impacts Ubuntu operating system security.

Solution

Configure the Graphical User Interface to not allow unattended or automatic login to the system.

Comment or remove the following lines in '/etc/lightdm/lightdm.conf' file:

#autologin-user=<username>
#autologin-user-timeout=0

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CAN_Ubuntu_16-04_LTS_V2R1_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|I, CCI|CCI-000366, Rule-ID|SV-214972r508033_rule, STIG-ID|UBTU-16-010330, STIG-Legacy|SV-90175, STIG-Legacy|V-75495, Vuln-ID|V-214972

Plugin: Unix

Control ID: b573c95f3554c1fa98627df3333a19afd22ef03eb59159dcc18fac0f99cf9020