STIGQter STIGQter: STIG Summary: Riverbed NetIM OS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

Ubuntu OS must require authentication upon booting into single-user and maintenance modes.

DISA Rule

SV-275566r1147748_rule

Vulnerability Number

V-275566

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

RIIM-OS-212010

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure Ubuntu OS to require a password for authentication upon booting into single-user and maintenance modes.

Note: GRUB password will need to be disabled prior to upgrade of the NETIM System if done unattended.

Generate an encrypted (grub) password for root by using the following command:

$ grub-mkpasswd-pbkdf2
Enter Password:
Reenter Password:
PBKDF2 hash of your password is grub.pbkdf2.sha512.10000.03255F190F0E2F7B4F0D1C3216012309162F022A7A636771

Using the hash from the output, modify the "/etc/grub.d/40_custom" file by using the following command to add a boot password:

$ sudo sed -i '$i set superusers=\"root\"\npassword_pbkdf2 root <hash>' /etc/grub.d/40_custom

where <hash> is the hash generated by grub-mkpasswd-pbkdf2 command.

Generate an updated "grub.conf" file with the new password by using the following command:

$ sudo update-grub

Check Contents

Verify Ubuntu OS requires a password for authentication upon booting into single-user and maintenance modes by using the following command:

$ sudo grep -i password /boot/grub/grub.cfg

password_pbkdf2 root grub.pbkdf2.sha512.10000.03255F190F0E2F7B4F0D1C3216012309162F022A7A636771

If the root password entry does not begin with "password_pbkdf2", this is a finding.

Vulnerability Number

V-275566

Documentable

False

Rule Version

RIIM-OS-212010

Severity Override Guidance

Verify Ubuntu OS requires a password for authentication upon booting into single-user and maintenance modes by using the following command:

$ sudo grep -i password /boot/grub/grub.cfg

password_pbkdf2 root grub.pbkdf2.sha512.10000.03255F190F0E2F7B4F0D1C3216012309162F022A7A636771

If the root password entry does not begin with "password_pbkdf2", this is a finding.

Check Content Reference

M

Target Key

5706