ALMA-09-006400 - AlmaLinux OS 9 must require a unique superuser's name upon booting into single-user and maintenance modes.

Information

Having a nondefault grub superuser username makes password-guessing attacks less effective.

Solution

Configure AlmaLinux OS 9 to have a unique username for the grub superuser account using the following commands:

$ sed -ri 's/root/superman/' /etc/grub.d/01_users

$ grub2-mkconfig -o /boot/grub2/grub.cfg

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CL_AlmaLinux_OS_9_V1R1_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|II, CCI|CCI-000213, Rule-ID|SV-269138r1050020_rule, STIG-ID|ALMA-09-006400, Vuln-ID|V-269138

Plugin: Unix

Control ID: 22fd5eec2a630e3859db8080d42a8ae083d9ffd3668b2e7c63c5ce47a48a86e0