You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Apr 17, 2023. It is now read-only.
From what I can tell, the call to grubby and subsequent parsing (looking for /^root=/) only looks at what device the root filesystem for that particular boot option, not if the boot loader is actually on removable media. This comes from my interpretation of "If the system is using an alternate boot loader on removable media..."
I was thinking a check to determine if /boot or /boot/efi were on removable media would need to include comparing the device from the output of the set root=($dev,$part) line in grub.cfg to the /sys/block/$dev/removable and confirming it is not removable.
Additionally, the STIG does not say that multiple instances of a grub.cfg are a finding but they may turn into a finding if they exist and the current form of V-72075 does not look for that.
The text was updated successfully, but these errors were encountered:
Sign up for freeto subscribe to this conversation on GitHub.
Already have an account?
Sign in.
From what I can tell, the call to
grubby
and subsequent parsing (looking for/^root=/
) only looks at what device the root filesystem for that particular boot option, not if the boot loader is actually on removable media. This comes from my interpretation of "If the system is using an alternate boot loader on removable media..."I was thinking a check to determine if
/boot
or/boot/efi
were on removable media would need to include comparing the device from the output of theset root=($dev,$part)
line ingrub.cfg
to the/sys/block/$dev/removable
and confirming it is not removable.Additionally, the STIG does not say that multiple instances of a grub.cfg are a finding but they may turn into a finding if they exist and the current form of V-72075 does not look for that.
The text was updated successfully, but these errors were encountered: