{"description": "<tt>GNOME</tt> allows users to create ad-hoc wireless connections through the\n<tt>NetworkManager</tt> applet. Wireless connections should be disabled by\nadding or setting <tt>disable-wifi-create</tt> to <tt>true</tt> in\n<tt>/etc/dconf/db/local.d/00-security-settings</tt>. For example:\n<pre>[org/gnome/nm-applet]\ndisable-wifi-create=true\n</pre>\nOnce the settings have been added, add a lock to\n<tt>/etc/dconf/db/local.d/locks/00-security-settings-lock</tt> to prevent user modification.\nFor example:\n<pre>/org/gnome/nm-applet/disable-wifi-create</pre>\nAfter the settings have been set, run <tt>dconf update</tt>.", "rationale": "Wireless network connections should not be allowed to be configured by general\nusers on a given system as it could open the system to backdoor attacks.", "severity": "medium", "references": {"cui": ["3.1.16"]}, "control_references": {}, "components": [], "identifiers": {}, "ocil_clause": "WIFI connections can be created through GNOME", "ocil": "To ensure that WIFI connections caanot be created, run the following command:\n<pre>$ gsettings get org.gnome.nm-applet disable-wifi-create</pre>\nIf properly configured, the output should be <tt>true</tt>.\nTo ensure that users cannot enable WIFI connection creation, run the following:\n<pre>$ grep wifi-create /etc/dconf/db/local.d/locks/*</pre>\nIf properly configured, the output should be\n<tt>/org/gnome/nm-applet/disable-wifi-create</tt>", "oval_external_content": null, "fixtext": "", "checktext": "", "vuldiscussion": "", "srg_requirement": "", "warnings": [], "conflicts": [], "requires": [], "policy_specific_content": {}, "platform": null, "platforms": [], "sce_metadata": {}, "inherited_platforms": ["package[gdm]"], "cpe_platform_names": [], "inherited_cpe_platform_names": ["package_gdm"], "bash_conditional": null, "fixes": {}, "title": "Disable WIFI Network Connection Creation in GNOME3", "definition_location": "/aptdata/openscap/scap-security-guide/linux_os/guide/system/software/gnome/gnome_network_settings/dconf_gnome_disable_wifi_create/rule.yml", "template": null}