1.7.4 Ensure GDM screen locks when the user is idle (Automated)
Profile
- Level 1 - Server
- Level 1 - Workstation
Description
GNOME Desktop Manager can make the screen lock automatically whenever the user is idle for some amount of time.
Rationale
Setting a lock-out value reduces the window of opportunity for unauthorized user access to another user's session that has been left unattended.
Audit Procedure
Command Line
Run the following command to verify that a user profile exists:
# grep -Psi "user-db|system-db" /etc/dconf/profile/*/*
/etc/dconf/profile/local:user-db:user
/etc/dconf/profile/local:system-db:local
Run the following commands to verify that the screen locks when the user is idle:
# gsettings get org.gnome.desktop.screensaver lock-delay
uint32 5
# gsettings get org.gnome.desktop.session idle-delay
uint32 900
# gsettings get org.gnome.desktop.screensaver lock-enabled
true
Notes:
lock-delay=uint32 {n}- should be5seconds or less and follow local site policyidle-delay=uint32 {n}- Should be900seconds (15 minutes) or less, not0(disabled) and follow local site policylock-enabled- must be set totruefor screen locks to lock when the user is idle
Expected Result
lock-delayshould be 5 seconds or lessidle-delayshould be 900 seconds or less (not 0)lock-enabledshould betrue
Remediation
Command Line
- IF - A user profile is already created run the following commands to enable screen locks when the user is idle:
# gsettings set org.gnome.desktop.screensaver lock-delay 5
# gsettings set org.gnome.desktop.session idle-delay 900
# gsettings set org.gnome.desktop.screensaver lock-enabled true
Note:
gsettingscommands in this section MUST be done from a command window on a graphical desktop or an error will be returned.The system must be restarted after all
gsettingsconfigurations have been set in order for CIS-CAT Assessor to appropriately assess.OR/IF - A user profile does not exist:
- Create or edit the user profile in the
/etc/dconf/profile/and verify it includes the following:
user-db:user
system-db:{NAME_OF_DCONF_DATABASE}
Note: local is the name of a dconf database used in the examples.
- Create the directory
/etc/dconf/db/local.d/if it doesn't already exist. - Create the key file
/etc/dconf/db/local.d/00-screensaverto provide information for thelocaldatabase:
Example key file:
# Specify the dconf path
[org/gnome/desktop/session]
# Number of seconds of inactivity before the screen goes blank
# Set to 0 seconds if you want to deactivate the screensaver.
idle-delay=uint32 180
# Specify the dconf path
[org/gnome/desktop/screensaver]
# Number of seconds after the screen is blank before locking the screen
lock-delay=uint32 0
# Ensure screen locks after inactivity
lock-enabled=true
Note: You must include the uint32 along with the integer key values as shown.
- Run the following command to update the system databases:
# dconf update
- Users must log out and back in again before the system-wide settings take effect.
References
CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 4.3 Configure Automatic Session Locking on Enterprise Assets | * | * | * |
| v7 | 16.11 Lock Workstation Sessions After Inactivity | * | * | * |
MITRE ATT&CK Mappings: T1461 | TA0027 | M1012