Check: PHTN-67-000005
VMware vSphere 6.7 Photon OS STIG:
PHTN-67-000005
(in versions v1 r6 through v1 r1)
Title
The Photon operating system must set a session inactivity timeout of 15 minutes or less. (Cat II impact)
Discussion
A session timeout is an action taken when a session goes idle for any reason. Rather than relying on the user to manually disconnect their session prior to going idle, the Photon operating system must be able to identify when a session has idled and take action to terminate the session. Satisfies: SRG-OS-000029-GPOS-00010, SRG-OS-000126-GPOS-00066, SRG-OS-000279-GPOS-00109
Check Content
At the command line, execute the following command: # cat /etc/profile.d/tmout.sh Expected result: TMOUT=900 readonly TMOUT export TMOUT mesg n 2>/dev/null If the file "tmout.sh" does not exist or the output does not look like the expected result, this is a finding.
Fix Text
Open /etc/profile.d/tmout.sh with a text editor and set its content to the following: TMOUT=900 readonly TMOUT export TMOUT mesg n 2>/dev/null
Additional Identifiers
Rule ID: SV-239077r856035_rule
Vulnerability ID: V-239077
Group Title: SRG-OS-000029-GPOS-00010
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000057 |
The information system initiates a session lock after the organization-defined time period of inactivity. |
CCI-000879 |
The organization terminates sessions and network connections when nonlocal maintenance is completed. |
CCI-002361 |
The information system automatically terminates a user session after organization-defined conditions or trigger events requiring session disconnect. |