1.4.3 Ensure authentication required for single user mode - rescue.service

Information

Requiring authentication in single user mode (rescue mode) prevents an unauthorized user from rebooting the system into single user to gain root privileges without credentials.

Solution

Edit /usr/lib/systemd/system/rescue.service and /usr/lib/systemd/system/emergency.service and set ExecStart to use ' /sbin/sulogin ': ExecStart=-/bin/sh -c '/sbin/sulogin; /usr/bin/systemctl --fail --no-block default'

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7, CSCv6|5.1

Plugin: Unix

Control ID: 059ff5f3e3a9cd31423bf0b8953afbc7112bf2a95010b364e486f1a85784307e