Check: RHEL-09-212015
RHEL 9 STIG:
RHEL-09-212015
(in versions v2 r3 through v1 r1)
Title
RHEL 9 must disable the ability of systemd to spawn an interactive boot process. (Cat II impact)
Discussion
Using interactive or recovery boot, the console user could disable auditing, firewalls, or other services, weakening system security.
Check Content
Verify that GRUB 2 is configured to disable interactive boot. Check that the current GRUB 2 configuration disables the ability of systemd to spawn an interactive boot process with the following command: $ sudo grubby --info=ALL | grep args | grep 'systemd.confirm_spawn' If any output is returned, this is a finding.
Fix Text
Configure the current GRUB 2 configuration to disable the ability of systemd to spawn an interactive boot process with the following command: $ sudo grubby --update-kernel=ALL --remove-args="systemd.confirm_spawn"
Additional Identifiers
Rule ID: SV-257788r1044838_rule
Vulnerability ID: V-257788
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |