The Oracle Linux operating system must disable the login screen user list for graphical user interfaces.
An XCCDF Rule
Description
Leaving the user list enabled is a security risk as it allows anyone with physical access to the system to enumerate known user accounts without authenticated access to the system.
- ID
- SV-256976r991589_rule
- Version
- OL07-00-010063
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure the operating system to disable the login screen user list for graphical user interfaces.
Create or edit the gdm profile in "/etc/dconf/profile/" to contain the following lines:
$ sudo vi /etc/dconf/profile/gdm