Check: RHEL-09-212015
RHEL 9 STIG:
RHEL-09-212015
(in versions v1 r3 through v1 r1)
Title
RHEL 9 must disable the ability of systemd to spawn an interactive boot process. (Cat II impact)
Discussion
Using interactive or recovery boot, the console user could disable auditing, firewalls, or other services, weakening system security.
Check Content
Verify that GRUB 2 is configured to disable interactive boot. Check that the current GRUB 2 configuration disables the ability of systemd to spawn an interactive boot process with the following command: $ sudo grubby --info=ALL | grep args | grep 'systemd.confirm_spawn' If any output is returned, this is a finding.
Fix Text
Configure RHEL 9 to allocate sufficient audit_backlog_limit to disable the ability of systemd to spawn an interactive boot process with the following command: $ sudo grubby --update-kernel=ALL --remove-args="systemd.confirm_spawn"
Additional Identifiers
Rule ID: SV-257788r925351_rule
Vulnerability ID: V-257788
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |