RHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require authentication upon booting into single-user mode and maintenance.
If the system does not require valid authentication before it boots into single-user or maintenance mode, anyone who invokes single-user or maintenance mode is granted privileged access to all files on the system. GRUB 2 is the default boot loader for RHEL 8 and is designed to require a password to boot into single-user mode or make modifications to the boot menu.
Check
Note: For systems that use BIOS, this is Not Applicable.
Check the unified configuration file where the grub2 password is stored: # grep -iw "GRUB2_PASSWORD" /boot/grub2/user.cfg GRUB2_PASSWORD=grub.pbkdf2.sha512.[password_hash]
If the "GRUB2_PASSWORD" entry exists and begins with "grub.pbkdf2.sha512", this is not a finding.
Note for legacy RHEL 8 deployments: Older versions of RHEL 8 may have stored this file in the EFI partition. If the file is not found in `/boot/grub2/`, check the legacy UEFI path: # grep -iw GRUB2_PASSWORD /boot/efi/EFI/redhat/user.cfg
If the "GRUB2_PASSWORD" entry does not exist in either location, or does not begin with "grub.pbkdf2.sha512", this is a finding.
Fix
Configure the system to require a GRUB bootloader password for the grub superusers account.
Use the "grub2-setpassword" command, which automatically creates and sets the correct permissions for the unified "/boot/grub2/user.cfg" file using the required PBKDF2 SHA512 hashing algorithm.
Generate the encrypted GRUB 2 password with the following command:
# grub2-setpassword Enter password: Confirm password:
Note: Do not manually edit the GRUB configuration files to set this password; always use the provided utility to ensure the correct hashing algorithm is applied and the file is placed in the active configuration directory.