LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-02-2014, 01:58 PM   #1
YankeePride13
Member
 
Registered: Aug 2012
Distribution: Ubuntu 10.04, CentOS 6.3, Windows 7
Posts: 262

Rep: Reputation: 55
Is a grub password necessary?


Hello,

It was recommended to me by a colleague to set a grub password to further harden one of my systems. I don't think this is necessary as if you have physical access to the system you can just use a live cd to get into the system. Is there any reason to set a grub password that you may have come across?
 
Old 10-02-2014, 02:01 PM   #2
szboardstretcher
Senior Member
 
Registered: Aug 2006
Location: Detroit, MI
Distribution: GNU/Linux systemd
Posts: 4,278

Rep: Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694
You can set the BIOS to only boot from HDD, then put a password on the BIOS, then put a password on GRUB. This is helpful in a shared rack, where no one is likely to actually tamper with your box, because that would be obvious, but they might 'accidentally' plug their crash cart into your server,.. and if you don't have it properly locked down then you are hosed.
 
Old 10-02-2014, 02:14 PM   #3
derekpock
Member
 
Registered: Apr 2012
Location: USA
Distribution: Elementary OS Luna
Posts: 83

Rep: Reputation: 4
I actually think just setting a bios boot password is better than both ideas. You can still get around grub with bios locked to HDD (remove the HDD). However. If you set a bios boot password, your bios will refuse to boot anything unless it's provided with the password. There are bios settings for this. Set a user password and enable password on boot - done! I do this with all computers of mine (except standalone servers which restart on their own). Yes, the password is usually a max of 8 characters, but that is better still than just a grub password.
 
Old 10-02-2014, 02:33 PM   #4
YankeePride13
Member
 
Registered: Aug 2012
Distribution: Ubuntu 10.04, CentOS 6.3, Windows 7
Posts: 262

Original Poster
Rep: Reputation: 55
The system in question is a server. I wouldn't put a bios boot password on a server. Thanks for the info, though.
 
Old 10-02-2014, 02:40 PM   #5
szboardstretcher
Senior Member
 
Registered: Aug 2006
Location: Detroit, MI
Distribution: GNU/Linux systemd
Posts: 4,278

Rep: Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694
Quote:
I actually think just setting a bios boot password is better than both ideas. You can still get around grub with bios locked to HDD (remove the HDD). However. If you set a bios boot password, your bios will refuse to boot anything unless it's provided with the password. There are bios settings for this. Set a user password and enable password on boot - done! I do this with all computers of mine (except standalone servers which restart on their own). Yes, the password is usually a max of 8 characters, but that is better still than just a grub password.
The CMOS password and Grub password is good enough for 'minor tampering' as i described above. If someone has full unimpeded access to your server then all bets are off.

Quote:
The system in question is a server. I wouldn't put a bios boot password on a server. Thanks for the info, though.
I agree with YankeePride13 there. I couldn't bring myself to have a password blocking a reboot, especially on a remote server.
 
Old 10-02-2014, 03:24 PM   #6
derekpock
Member
 
Registered: Apr 2012
Location: USA
Distribution: Elementary OS Luna
Posts: 83

Rep: Reputation: 4
Right. I wouldn't recommend bios passwords on servers. I was unaware that is what you were asking about.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
GRUB security. -How do I properly set, and double check the grub bootloader password? bwilky11 Debian 3 11-02-2012 08:22 PM
how to change root password without knowing the grub password ramesh.mimit Red Hat 8 10-15-2011 05:12 AM
change Root Password even if the password in the grub is also set sheelnidhi Linux - General 6 08-30-2006 07:27 AM
Setting password on grub, wha to do after changing default values in /boot/grub/menu. sarajevo Linux - Security 1 08-17-2005 08:01 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:10 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration