UCF STIG Viewer Logo

The Solaris system EEPROM security-mode parameter must be set to full or command mode.


Overview

Finding ID Version Rule ID IA Controls Severity
V-226419 GEN000000-SOL00300 SV-226419r603265_rule Medium
Description
If the EEPROM security-mode parameter is not set to full or command, then unauthorized access to system EEPROM can take place. In normal situations, when the system is in a controlled access area and it is desirable to have it automatically reboot upon loss of and restoring of power, for instance, then command mode with the autoboot parameter set to true is recommended.
STIG Date
Solaris 10 SPARC Security Technical Implementation Guide 2020-12-04

Details

Check Text ( C-28580r482618_chk )
If the system does not have an OBP / EEPROM, this is not applicable.

# eeprom | grep security-mode

If the EEPROM security-mode parameter is not set to full or command, this is a finding.
Fix Text (F-28568r482619_fix)
Set the system EEPROM security-mode parameter to full or command.

# eeprom security-mode=full
OR
# eeprom security-mode=command

The system will prompt the user for a password. This should be securely stored.