Check: GEN000000-SOL00300
Solaris 10 SPARC STIG:
GEN000000-SOL00300
(in versions v2 r4 through v1 r19)
Title
The Solaris system EEPROM security-mode parameter must be set to full or command mode. (Cat II impact)
Discussion
If the EEPROM security-mode parameter is not set to full or command, then unauthorized access to system EEPROM can take place. In normal situations, when the system is in a controlled access area and it is desirable to have it automatically reboot upon loss of and restoring of power, for instance, then command mode with the autoboot parameter set to true is recommended.
Check Content
If the system does not have an OBP / EEPROM, this is not applicable. # eeprom | grep security-mode If the EEPROM security-mode parameter is not set to full or command, this is a finding.
Fix Text
Set the system EEPROM security-mode parameter to full or command. # eeprom security-mode=full OR # eeprom security-mode=command The system will prompt the user for a password. This should be securely stored.
Additional Identifiers
Rule ID: SV-226419r603265_rule
Vulnerability ID: V-226419
Group Title: SRG-OS-000480
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |