Skip to content

Verify that Interactive Boot is Disabled

An XCCDF Rule

Description

Red Hat Enterprise Linux CoreOS 4 systems support an "interactive boot" option that can be used to prevent services from being started. On a Red Hat Enterprise Linux CoreOS 4 system, interactive boot can be enabled by providing a 1, yes, true, or on value to the systemd.confirm_spawn kernel argument.

Rationale

Using interactive boot, the console user could disable auditing, firewalls, or other services, weakening system security.

ID
xccdf_org.ssgproject.content_rule_coreos_disable_interactive_boot
Severity
Medium
References
Updated