UCF STIG Viewer Logo

The Photon operating system must set a session inactivity timeout of 15 minutes or less.


Overview

Finding ID Version Rule ID IA Controls Severity
V-256482 PHTN-30-000005 SV-256482r887120_rule Medium
Description
A session timeout is an action taken when a session goes idle for any reason. Rather than relying on the user to manually disconnect their session prior to going idle, the Photon operating system must be able to identify when a session has idled and take action to terminate the session. Satisfies: SRG-OS-000029-GPOS-00010, SRG-OS-000279-GPOS-00109, SRG-OS-000126-GPOS-00066
STIG Date
VMware vSphere 7.0 vCenter Appliance Photon OS Security Technical Implementation Guide 2023-12-01

Details

Check Text ( C-60157r887118_chk )
At the command line, run the following command:

# cat /etc/profile.d/tmout.sh

Expected result:

TMOUT=900
readonly TMOUT
export TMOUT
mesg n 2>/dev/null

If the file "tmout.sh" does not exist or the output does not look like the expected result, this is a finding.
Fix Text (F-60100r887119_fix)
Navigate to and open:

/etc/profile.d/tmout.sh

Set its content to the following:

TMOUT=900
readonly TMOUT
export TMOUT
mesg n 2>/dev/null