{"description": "By default, DConf provides a standard user profile. This profile contains a list\nof DConf configuration databases. The user profile and database always take the\nhighest priority. As such the DConf User profile should always exist and be\nconfigured correctly.\n<br /><br />\n\nTo make sure that the gdm profile is configured correctly, the <tt>/etc/dconf/profile/gdm</tt>\nshould be set as follows:\n<pre>user-db:user\nsystem-db:gdm\n</pre>\nTo make sure that the user profile is configured correctly, the <tt>/etc/dconf/profile/user</tt>\nshould be set as follows:\n<pre>user-db:user\nsystem-db:local\n</pre>", "rationale": "Failure to have a functional DConf profile prevents GNOME3 configuration settings\nfrom being enforced for all users and allows various security risks.", "severity": "high", "references": {"pcidss4": ["8.2.8", "8.2"]}, "control_references": {"pcidss4": ["8.2.8", "8.2"]}, "components": [], "identifiers": {}, "ocil_clause": "DConf User profile does not exist or is not configured correctly", "ocil": "To verify that the DConf User profile is configured correctly, run the following\ncommand:\n\n<pre>$ cat /etc/dconf/profile/gdm</pre>\nThe output should show the following:\n<pre>user-db:user\nsystem-db:gdm</pre>\n<pre>$ cat /etc/dconf/profile/user</pre>\nThe output should show the following:\n<pre>user-db:user\nsystem-db:local", "oval_external_content": null, "fixtext": "", "checktext": "", "vuldiscussion": "", "srg_requirement": "", "warnings": [], "conflicts": [], "requires": [], "policy_specific_content": {}, "platform": "system_with_kernel", "platforms": ["system_with_kernel"], "sce_metadata": {}, "inherited_platforms": ["package[gdm]"], "cpe_platform_names": ["system_with_kernel"], "inherited_cpe_platform_names": ["package_gdm"], "bash_conditional": null, "fixes": {}, "title": "Configure GNOME3 DConf User Profile", "definition_location": "/aptdata/openscap/scap-security-guide/linux_os/guide/system/software/gnome/enable_dconf_user_profile/rule.yml", "template": null}