Bug 867945
Summary: | Setting idle_delay key has no effect | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 6 | Reporter: | Jiri Koten <jkoten> |
Component: | gnome-screensaver | Assignee: | Ray Strode [halfline] <rstrode> |
Status: | CLOSED NOTABUG | QA Contact: | Desktop QE <desktop-qa-list> |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | 6.3 | CC: | ayadav, chadmvaughn, dave.muth, dbasant, mark.a.hale, tpelka |
Target Milestone: | rc | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2013-05-10 14:27:40 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 835616, 960054 |
Description
Jiri Koten
2012-10-18 15:55:44 UTC
This request was not resolved in time for the current release. Red Hat invites you to ask your support representative to propose this request, if still desired, for consideration in the next release of Red Hat Enterprise Linux. I agree with the original requester. This inability to lock down the idle_delay setting is a major flaw. We are required to lock this setting to meet government security requirements. This is critical and must be fixed in the next release. I can confirm that this still exists in the latest Redhat Enterprise 6.4 release. The bug still exists. I agree that it's a big problem for U.S. federal government computers and fed contractors. I had the same problem (w/RHEL 6.4)and it is a documentation issue. I finally downloaded the gnome-screensaver SRPM and examined the source code to resolve the issue: [root@elocoslinsec src]# grep -i gnome_session_dir gnome-screensaver-preferences.c #define GNOME_SESSION_DIR "/desktop/gnome/session" #define KEY_ACTIVATE_DELAY GNOME_SESSION_DIR "/idle_delay" [root@elocoslinsec src]# As you can see, the idle_delay variable is stored in /desktop/gnome/session, not /apps/gnome-screensaver. The correct command to restrict users to a 15 minute timeout before screen lock is: # gconftool-2 --direct --config-source xml:readwrite:/etc/gconf/gconf.xml.mandatory --type int --set /desktop/gnome/session/idle_delay 15 I have verified that this works. I believe all that needs to be done is to update the RHEL "Security Guide" with this information. Thanks. Thanks Mark! I confirm that the fix using /desktop/gnome/session as you listed above does lock the idle delay. Thanks for clarifying. sounds like this issue is resolved, so closing. Please reopen if there is further engineering attention required. |