APPL-26-005070 - The macOS system must enable Authenticated Root.

Information

Authenticated Root must be enabled.

When Authenticated Root is enabled, the macOS is booted from a signed volume that is cryptographically protected to prevent tampering with the system volume.

Note: Authenticated Root is enabled by default on macOS systems.

WARNING: If more than one partition with macOS is detected, the csrutil command will hang awaiting input.

Solution

Configure the macOS system to enable authenticated root with the following command:

/usr/bin/csrutil authenticated-root enable

Note: To reenable "Authenticated Root", boot the affected system into "Recovery" mode, launch "Terminal" from the "Utilities" menu, and run the command.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_macOS_26_V1R1_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|II, CCI|CCI-000213, Rule-ID|SV-277175r1149394_rule, STIG-ID|APPL-26-005070, Vuln-ID|V-277175

Plugin: Unix

Control ID: 4c14ce1ac3c8ad5ac97fa2db745851d855a94d82f1819b4e3d4fc137bd90fb60