The system must display a publicly-viewable pattern during a graphical desktop environment session lock.

From Red Hat Enterprise Linux 6 Security Technical Implementation Guide

Part of SRG-OS-000031

Associated with: CCI-000060

SV-50440r3_rule The system must display a publicly-viewable pattern during a graphical desktop environment session lock.

Vulnerability discussion

Setting the screensaver mode to blank-only conceals the contents of the display from passersby.

Check content

If the GConf2 package is not installed, this is not applicable. To ensure the screensaver is configured to be blank, run the following command: $ gconftool-2 --direct --config-source xml:readwrite:/etc/gconf/gconf.xml.mandatory --get /apps/gnome-screensaver/mode If properly configured, the output should be "blank-only". If it is not, this is a finding.

Fix text

Run the following command to set the screensaver mode in the GNOME desktop to a blank screen: # gconftool-2 \ --direct \ --config-source xml:readwrite:/etc/gconf/gconf.xml.mandatory \ --type string \ --set /apps/gnome-screensaver/mode blank-only

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer