STIGQter STIGQter: STIG Summary: Solaris 10 X86 Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 22 Jan 2021:

For systems capable of using GRUB, the system must be configured with GRUB as the default boot loader unless another boot loader has been authorized, justified, and documented using site-defined procedures.

DISA Rule

SV-220123r603266_rule

Vulnerability Number

V-220123

Group Title

SRG-OS-000480

Rule Version

GEN008660

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the system to use the GRUB bootloader.

Check Contents

This check applies to the global zone only. Determine the type of zone that you are currently securing.

# zonename

If the command output is "global", this check applies.

On systems that have a ZFS root, the active menu.lst file is typically located at /pool-name/boot/grub/menu.lst where "pool-name" is the mount point for the top-level dataset.

On systems that have a UFS root, the active menu.lst file is typically located at /boot/grub/menu.lst. To locate the active GRUB menu, use the bootadm command with the list-menu option:

# bootadm list-menu

Determine if the system uses the GRUB boot loader.

Procedure:
# more /pool-name/boot/grub/menu.lst
or
# more /boot/grub/menu.lst

If menu.lst does not exist, this is a finding.

Vulnerability Number

V-220123

Documentable

False

Rule Version

GEN008660

Severity Override Guidance

This check applies to the global zone only. Determine the type of zone that you are currently securing.

# zonename

If the command output is "global", this check applies.

On systems that have a ZFS root, the active menu.lst file is typically located at /pool-name/boot/grub/menu.lst where "pool-name" is the mount point for the top-level dataset.

On systems that have a UFS root, the active menu.lst file is typically located at /boot/grub/menu.lst. To locate the active GRUB menu, use the bootadm command with the list-menu option:

# bootadm list-menu

Determine if the system uses the GRUB boot loader.

Procedure:
# more /pool-name/boot/grub/menu.lst
or
# more /boot/grub/menu.lst

If menu.lst does not exist, this is a finding.

Check Content Reference

M

Target Key

4061

Comments