ALMA-09-013550 - AlmaLinux OS 9 must disable the ability of systemd to spawn an interactive boot process.

Information

Using interactive or recovery boot, the console user could disable auditing, firewalls, or other services, weakening system security.

Solution

Configure AlmaLinux OS 9 to disable the ability of systemd to spawn an interactive boot process with the following command:

$ grubby --update-kernel=ALL --remove-args="systemd.confirm_spawn"

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CL_AlmaLinux_OS_9_V1R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-269199r1050081_rule, STIG-ID|ALMA-09-013550, Vuln-ID|V-269199

Plugin: Unix

Control ID: 548482a6294e1a440e458326573c4544d51c9792d45398b1569e06318a7e67cb