Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-1802

Add new rule to enforce idle session timeout (StopIdleSessionSec)

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • None
    • None
    • rhel-security-compliance
    • ssg_security
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • None
    • None
    • Release Note Not Required
    • Hide
      Feature, enhancement (describe the feature or enhancement from the user’s point of view):
      Reason (why has the feature or enhancement been implemented):
      Result (what is the current user experience):
      Show
      Feature, enhancement (describe the feature or enhancement from the user’s point of view): Reason (why has the feature or enhancement been implemented): Result (what is the current user experience):
    • None
    • 57,005

      Description of problem:
      New option is introduced in SystemD (See Bug 2100464). This option allows to set timeout for idle sessions globally, which can replace no longer available sshd session timeout mechanism using ClientAliveCountMax.

      For the reason, we need the rule covering it.

      Usage seems to be configuration of logind.conf in a form:
      [Login]
      StopIdleSessionSec=<time>

      Version-Release number of selected component (if applicable):
      scap-security-guide-0.1.63-5.el9

      How reproducible:
      reliably

      Steps to Reproduce:
      1. look at the list of rules
      2.
      3.

      Actual results:
      rule does not exist

      Expected results:
      rule exists

      Additional info:

              vpolasek@redhat.com Vojtech Polasek
              mhaicman@redhat.com Marek Haičman
              Vojtech Polasek Vojtech Polasek
              Jiri Jaburek Jiri Jaburek
              Votes:
              0 Vote for this issue
              Watchers:
              12 Start watching this issue

                Created:
                Updated:
                Resolved: