STIGQter STIGQter: STIG Summary: Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

Ubuntu 22.04 LTS, when booted, must require authentication upon booting into single-user and maintenance modes.

DISA Rule

SV-260470r1137691_rule

Vulnerability Number

V-260470

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

UBTU-22-212010

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure Ubuntu 22.04 LTS to require a password for authentication upon booting into single-user and maintenance modes.

Generate an encrypted (grub) password for root by using the following command:

$ grub-mkpasswd-pbkdf2
Enter Password:
Reenter Password:
PBKDF2 hash of your password is grub.pbkdf2.sha512.10000.03255F190F0E2F7B4F0D1C3216012309162F022A7A636771

Using the hash from the output, modify the "/etc/grub.d/40_custom" file by using the following command to add a boot password:

$ sudo sed -i '$i set superusers=\"root\"\npassword_pbkdf2 root <hash>' /etc/grub.d/40_custom

where <hash> is the hash generated by grub-mkpasswd-pbkdf2 command.

Generate an updated "grub.conf" file with the new password by using the following command:

$ sudo update-grub

Check Contents

Verify Ubuntu 22.04 LTS requires a password for authentication upon booting into single-user and maintenance modes by using the following command:

$ sudo grep -i password /boot/grub/grub.cfg

password_pbkdf2 root grub.pbkdf2.sha512.10000.03255F190F0E2F7B4F0D1C3216012309162F022A7A636771

If the root password entry does not begin with "password_pbkdf2", this is a finding.

Vulnerability Number

V-260470

Documentable

False

Rule Version

UBTU-22-212010

Severity Override Guidance

Verify Ubuntu 22.04 LTS requires a password for authentication upon booting into single-user and maintenance modes by using the following command:

$ sudo grep -i password /boot/grub/grub.cfg

password_pbkdf2 root grub.pbkdf2.sha512.10000.03255F190F0E2F7B4F0D1C3216012309162F022A7A636771

If the root password entry does not begin with "password_pbkdf2", this is a finding.

Check Content Reference

M

Target Key

5594