An XCCDF Group - A logical subset of the XCCDF Benchmark
SystemD
Ctrl-Alt-Del
CtrlAltDelBurstAction
/etc/systemd/system.conf
CtrlAltDelBurstAction=none
ln -sf /dev/null /etc/systemd/system/ctrl-alt-del.target
systemctl mask ctrl-alt-del.target
/usr/lib/systemd/system/ctrl-alt-del.service
vlock
$ apt-get install vlock
cac
default
other
opensc-pkcs11
$ apt-get install opensc-pkcs11
libpam-pkcs11
$ apt-get install libpam-pkcs11
cert_policy
/etc/pam_pkcs11/pam_pkcs11.conf
ca
cert_policy = ca, ocsp_on, signature;
ocsp_on
crl_auto
crl_offline
cert_policy = ca,signature,ocsp_on,crl_auto;
pam_pkcs11.so
etc/pam.d/common-auth
# grep pam_pkcs11.so /etc/pam.d/common-auth auth [success=2 default=ignore] pam_pkcs11.so
use_mappers
pwent
$ grep ^use_mappers /etc/pam_pkcs11/pam_pkcs11.conf use_mappers = pwent