The Photon operating system must require authentication upon booting into single-user and maintenance modes.
An XCCDF Rule
Description
<VulnDiscussion>If the system does not require authentication before it boots into single-user mode, anyone with console access to the system can trivially access all files on the system. GRUB2 is the boot loader for Photon OS and can be configured to require a password to boot into single-user mode or make modifications to the boot menu. Note: Photon does not support building grub changes via grub2-mkconfig.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-258824r933533_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Before proceeding, ensure a snapshot is taken to rollback if needed.
At the command line, run the following command to generate a grub password:
# grub2-mkpasswd-pbkdf2