Prevent user from disabling the screen lock
An XCCDF Rule
Description
Thetmux
terminal multiplexer is used to implement
automatic session locking. It should not be listed in
/etc/shells
.
Rationale
Not listing tmux
among permitted shells
prevents malicious program running as user
from lowering security by disabling the screen lock.
- ID
- xccdf_org.ssgproject.content_rule_no_tmux_in_shells
- Severity
- Low
- References
- Updated
Remediation Templates
A Kubernetes Patch
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
config:
ignition:
version: 3.1.0