SV-217144r603262_rule
V-217144
SRG-OS-000080-GPOS-00048
SLES-12-010430
CAT II
10
Note: If the system does not use a basic input/output system (BIOS) this requirement is Not Applicable.
Configure the SUSE operating system to encrypt the boot password.
Generate an encrypted (GRUB2) password for root with the following command:
# sudo grub2-mkpasswd-pbkdf2
Enter Password:
Reenter Password:
PBKDF2 hash of your password is grub.pbkdf2.sha512.10000.MFU48934NJD84NF8NSD39993JDHF84NG
Using the hash from the output, modify the "/etc/grub.d/40_custom" file with the following command to add a password for the boot user entry:
# cat << EOF
set superusers="boot"
password_pbkdf2 boot grub.pbkdf2.sha512.VeryLongString
EOF
Generate an updated "grub.conf" file with the new password using the following commands:
# sudo grub2-mkconfig --output=/tmp/grub2.cfg
# sudo mv /tmp/grub2.cfg /boot/grub2/grub.cfg
Verify that the SUSE operating system has set an encrypted root password.
Note: If the system does not use a basic input/output system (BIOS) this requirement is Not Applicable.
Check that the encrypted password is set for a boot user with the following command:
# sudo cat /boot/grub2/grub.cfg | grep -i password
password_pbkdf2 boot grub.pbkdf2.sha512.10000.VeryLongString
If the boot user password entry does not begin with "password_pbkdf2", this is a finding.
V-217144
False
SLES-12-010430
Verify that the SUSE operating system has set an encrypted root password.
Note: If the system does not use a basic input/output system (BIOS) this requirement is Not Applicable.
Check that the encrypted password is set for a boot user with the following command:
# sudo cat /boot/grub2/grub.cfg | grep -i password
password_pbkdf2 boot grub.pbkdf2.sha512.10000.VeryLongString
If the boot user password entry does not begin with "password_pbkdf2", this is a finding.
M
4033