SUSE operating systems with Unified Extensible Firmware Interface (UEFI) implemented must require authentication upon booting into single-user mode and maintenance.
An XCCDF Rule
Description
If the system allows a user to boot into single-user or maintenance mode without authentication, any user that invokes single-user or maintenance mode is granted privileged access to all system information. If the system is running in EFI mode, SLES 12 by default will use GRUB 2 EFI as the boot loader.
- ID
- SV-217145r958472_rule
- Version
- SLES-12-010440
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Note: If the system does not use UEFI, this requirement is Not Applicable.
Configure the SUSE operating system to encrypt the boot password.
Generate an encrypted (GRUB 2) password for a boot user with the following command: