APPL-15-005070 - The macOS system must enable Authenticated Root.

Information

Authenticated Root must be enabled.

When Authenticated Root is enabled, the macOS is booted from a signed volume that is cryptographically protected to prevent tampering with the system volume.

NOTE: Authenticated Root is enabled by default on macOS systems.

WARNING: If more than one partition with macOS is detected, the csrutil command will hang awaiting input.

Solution

Configure the macOS system to enable authenticated root with the following command:

/usr/bin/csrutil authenticated-root enable

NOTE: To reenable 'Authenticated Root', boot the affected system into 'Recovery' mode, launch 'Terminal' from the 'Utilities' menu, and run the command.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_macOS_15_V1R1_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|II, CCI|CCI-000213, Rule-ID|SV-268565r1034635_rule, STIG-ID|APPL-15-005070, Vuln-ID|V-268565

Plugin: Unix

Control ID: 3d2e0440b44cb1f649524b6aa2e8633b60d1270fc8b56d761c3c41f03f4546e7