Skip to content

Rule logind_session_timeout is misaligned with DISA #14540

@jan-cerny

Description

@jan-cerny

Description of problem:

Rule logind_session_timeout is misaligned with DISA STIG for RHEL 9 V2R7. We discovered this issue in weekly productization.

The problem is that CaC check finds the setting in the directory /etc/systemd/logind.conf.d at /etc/systemd/logind.conf.d/oscap-idle-sessions.conf but DISA requires it to be present in the /etc/systemd/logind.conf.

SCAP Security Guide Version:

Current upstream master branch as of 2026-03-08 as of HEAD c4ab25f

Operating System Version:

RHEL-9.2.0-updates-20260306.0
RHEL-9.4.0-updates-20260306.1
RHEL-9.6.0-updates-20260306.0
RHEL-9.7.0-updates-20260306.0

Steps to Reproduce:

  1. /scanning/disa-alignment/oscap
  2. /scanning/disa-alignment/anaconda
  3. /scanning/disa-alignment/ansible

Actual Results:

SSG result: pass, DISA result(s): SV-258077r1155659_rule:fail

Expected Results:

SSG result: pass, DISA result(s): SV-258077r1155659_rule:pass

Additional Information/Debugging Steps:

no

Metadata

Metadata

Assignees

No one assigned

    Labels

    RHEL9Red Hat Enterprise Linux 9 product related.STIGSTIG Benchmark related.blockedIssue that can't be fixed in content.productization-issueIssue found in upstream stabilization process.triaged

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions