New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CCE-28305-1] shutdown_button #7

Closed
macosforgebot opened this Issue May 29, 2013 · 4 comments

Comments

@macosforgebot
Copy link

macosforgebot commented May 29, 2013

@DewSecGitHub originally submitted this as ticket:6

  • Version: Beta
  • Keywords: Settings, Review

CCE#: CCE-28305-1
Setting Name: shutdown_button
Description:
Hide or display the shutdown button in the login window.

Parameters: N / A
Technical Mechanism: In loginwindow.plist, set the ShutDownDisabled key = true to hide the button. If the key does not exist, the button is displayed.

Reference: OSX 10.5 DoD Recommended Settings document.

Function: Authentication

Rationale: The SOHO profile profile places more system management burdens on users.


SOHO: display the button
Enterprise: hide the button
SSLF: hide the button


Additional Mechanism: N / A


OVAL Content: N / A


Comment:

@macosforgebot

This comment has been minimized.

Copy link

macosforgebot commented May 29, 2013

@DewSecGitHub originally submitted this as comment:1:⁠ticket:6

  • Type changed from T1 - Defect to T4 - Review
  • Status changed from new to accepted
  • Keywords Settings, Review added
  • Priority changed from P6 - Not Set to P5 - Investigate
  • Severity changed from S8 - Unknown to S9 - Not Applicable
  • Component changed from C0 - Unassigned to C8 - Settings
  • Milestone changed from M1 - Unassigned to M4 - Weekly Review
@macosforgebot

This comment has been minimized.

Copy link

macosforgebot commented May 30, 2013

dubs@… originally submitted this as comment:2:⁠ticket:6


Redundant with [CCE-28301-0] sleep_restart_shutdown_buttons

Also is this really a security setting? If I can touch the keyboard or computer I can just restart it with the physical button.

@macosforgebot

This comment has been minimized.

Copy link

macosforgebot commented Jun 6, 2013

plink53@… originally submitted this as comment:3:⁠ticket:6


Replying to dubs@…:

Redundant with [CCE-28301-0] sleep_restart_shutdown_buttons

Also is this really a security setting? If I can touch the keyboard or computer I can just restart it with the physical button.

As with the others, there are multiple ways to configure these settings so all must be addressed. As for whether they are a security setting, it depends on whether you feel good business practices constitute a security setting. Just because there is a relatively easy way around something doesn't mean you shouldn't disable the visible presentation on something. Disabling the shutdown key means someone passing by can't shut a system down by simply clicking on the screen.

@macosforgebot

This comment has been minimized.

Copy link

macosforgebot commented Aug 6, 2014

blank@… originally submitted this as comment:6:⁠ticket:6

  • Status changed from accepted to closed
  • Resolution set to R8 - Completed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment