RHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require a unique superusers name upon booting into single-user mode and maintenance.

STIG ID: RHEL-08-010141  |  SRG: SRG-OS-000080-GPOS-00048 |  Severity: medium (CAT II)  |  CCI: CCI-000213 |  Vulnerability Id: V-244521

Vulnerability Discussion

If the system does not require valid authentication before it boots into single-user or maintenance mode, anyone who invokes single-user or maintenance mode is granted privileged access to all files on the system. GRUB 2 is the default boot loader for RHEL 8 and is designed to require a password to boot into single-user mode or make modifications to the boot menu.

The GRUB 2 superuser account is an account of last resort. Establishing a unique username for this account hardens the boot loader against brute force attacks. Due to the nature of the superuser account database being distinct from the OS account database, this allows the use of a username that is not among those within the OS account database. Examples of nonunique superusers names are root, superuser, unlock, etc.

Check

Note: For systems that use BIOS, this is Not Applicable.

Verify that a unique name is set as the "superusers" account.

Search the unified GRUB 2 configuration file for the superusers definition:
# grep -iw "superusers" /boot/grub2/grub.cfg
set superusers="[someuniquestringhere]"
export superusers

If "superusers" is not defined, or if the defined superuser name is identical to a standard OS administrative account name (such as "root", "admin", "administrator", "superuser", or "unlock"), this is a finding.

Note for legacy RHEL 8 deployments: If the system is running an older minor release where GRUB paths are not unified, check the legacy UEFI path:
# grep -iw "superusers" /boot/boot/efi/EFI/redhat/grub.cfg

Fix

Configure the system to have a unique name for the GRUB 2 superusers account.

1. Edit the "/etc/grub.[...](asc_slot://start-slot-10)d/01_users" file to declare the custom superuser name:

# pfedit /etc/grub.d/01_users

Ensure the following lines exist or are modified:
set superusers="[someuniquestringhere]"
export superusers
password_pbkdf2 [someuniquestringhere] ${GRUB2_PASSWORD}
(Replace "[someuniquestringhere]" with a unique string that does not match any existing OS user account name.)

2. Regenerate the GRUB 2 configuration using the unified configuration utility:

# grub2-mkconfig -o /boot/grub2/grub.cfg

Note for legacy RHEL 8 deployments: If using an older minor release requiring the legacy partition file path, output the config to:
# grub2-mkconfig -o /boot/efi/EFI/redhat/grub.cfg