SV-260470r1137691_rule
V-260470
SRG-OS-000080-GPOS-00048
UBTU-22-212010
CAT I
10
Configure Ubuntu 22.04 LTS to require a password for authentication upon booting into single-user and maintenance modes.
Generate an encrypted (grub) password for root by using the following command:
$ grub-mkpasswd-pbkdf2
Enter Password:
Reenter Password:
PBKDF2 hash of your password is grub.pbkdf2.sha512.10000.03255F190F0E2F7B4F0D1C3216012309162F022A7A636771
Using the hash from the output, modify the "/etc/grub.d/40_custom" file by using the following command to add a boot password:
$ sudo sed -i '$i set superusers=\"root\"\npassword_pbkdf2 root <hash>' /etc/grub.d/40_custom
where <hash> is the hash generated by grub-mkpasswd-pbkdf2 command.
Generate an updated "grub.conf" file with the new password by using the following command:
$ sudo update-grub
Verify Ubuntu 22.04 LTS requires a password for authentication upon booting into single-user and maintenance modes by using the following command:
$ sudo grep -i password /boot/grub/grub.cfg
password_pbkdf2 root grub.pbkdf2.sha512.10000.03255F190F0E2F7B4F0D1C3216012309162F022A7A636771
If the root password entry does not begin with "password_pbkdf2", this is a finding.
V-260470
False
UBTU-22-212010
Verify Ubuntu 22.04 LTS requires a password for authentication upon booting into single-user and maintenance modes by using the following command:
$ sudo grep -i password /boot/grub/grub.cfg
password_pbkdf2 root grub.pbkdf2.sha512.10000.03255F190F0E2F7B4F0D1C3216012309162F022A7A636771
If the root password entry does not begin with "password_pbkdf2", this is a finding.
M
5594