SOL-11.1-080130 - The system must require passwords to change the boot device settings. (SPARC)

Information

Setting the EEPROM password helps prevent attackers who gain physical access to the system console from booting from an external device (such as a CD-ROM or floppy).

Solution

The root role is required.

This action applies to the global zone only. Determine the zone that you are currently securing.

# zonename

If the command output is 'global', this action applies.

# eeprom security-mode=command


After entering the command above, the administrator will be prompted for a password. This password will be required to authorize any future command issued at boot-level on the system (the ok or > prompt) except for the normal multi-user boot command (i.e., the system will be able to reboot unattended).

Write down the password and store it in a secure location.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_SPARC_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-216454r959010_rule, STIG-ID|SOL-11.1-080130, STIG-Legacy|SV-60875, STIG-Legacy|V-48003, Vuln-ID|V-216454

Plugin: Unix

Control ID: 2b2badc117bc1b83872ac594cf9a6791510dd7a737a16af6eed044d17ef1dc5b