ALMA 9 must require authentication upon booting into single-user and maintenance modes.

STIG ID: ALMA-09-006290  |  SRG: SRG-OS-000080-GPOS-00048 |  Severity: medium (CAT II)  |  CCI: CCI-000213 |  Vulnerability Id: V-269137

Vulnerability Discussion

Password protection on the boot loader configuration ensures users with physical access cannot trivially alter important bootloader settings. These include which kernel to use, and whether to enter single-user mode.

Check

Verify that ALMA 9 requires a password for the GRUB 2 bootloader to prevent unauthorized modifications to boot parameters.

Check the unified configuration file where the GRUB 2 password is stored:

# sudo grep -iw "GRUB2_PASSWORD" /boot/grub2/user.cfg
GRUB2_PASSWORD=grub.pbkdf2.sha512.[password_hash]

If the "GRUB2_PASSWORD" entry does not exist, is commented out, or if the hash does not begin with "grub.pbkdf2.sha512", this is a finding.

Fix

Configure AlmaLinux OS 9 to require a grub bootloader password for the grub superuser account.

Generate an encrypted grub2 password for the grub superuser account with the following command:

$ grub2-setpassword
Enter password:
Confirm password: