STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 4 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Oracle Linux 8 Security Technical Implementation Guide

V-248671

CAT II (Medium)

OL 8 must enable a user session lock until that user reestablishes access using established identification and authentication procedures for graphical user sessions.

Rule ID

SV-248671r1015040_rule

STIG

Oracle Linux 8 Security Technical Implementation Guide

Version

V2R8

CCIs

CCI-000056CCI-000057CCI-000058

Discussion

To establish acceptance of the application usage policy, a click-through banner at system logon is required. The system must prevent further activity until the user executes a positive action to manifest agreement by clicking on a box indicating "OK". Satisfies: SRG-OS-000028-GPOS-00009, SRG-OS-000030-GPOS-00011

Check Content

Note: This requirement assumes the use of the OL 8 default graphical user interface, Gnome Shell. If the system does not have any graphical user interface installed, this requirement is Not Applicable. 
 
Verify the operating system enables a user's session lock until that user reestablishes access using established identification and authentication procedures with the following command: 
 
$ sudo gsettings get org.gnome.desktop.screensaver lock-enabled 
 
true 
 
If the setting is "false", this is a finding.

Fix Text

Configure OL 8 to enable a user's session lock until that user reestablishes access using established identification and authentication procedures. 
 
Create a database to contain the system-wide screensaver settings (if it does not already exist) with the following example: 
 
$ sudo vi /etc/dconf/db/local.d/00-screensaver 
 
Edit the "[org/gnome/desktop/screensaver]" section of the database file and add or update the following lines: 
 
# Set this to true to lock the screen when the screensaver activates 
lock-enabled=true 
 
Update the system databases: 
 
$ sudo dconf update