-
Feature
-
Resolution: Obsolete
-
Major
-
None
-
None
-
BU Product Work
-
False
-
-
False
-
33% To Do, 0% In Progress, 67% Done
-
0
-
Program Call
Feature Overview (aka. Goal Summary)
In high physical-security environments, it would be considered useful to lock down the grub command-line & menu. An attacker with access to the BMC/console could drop to single user mode or boot an older version of the OS with a known vulnerability.
Goals (aka. expected user outcomes)
The admin shouls be able to set the grub bootloader password for machines in new cluster installations only (see: COS-2316)
Out of Scope
This TP does not introduce support for day 2 changes of this password. That is covered in OCPSTRAT-113.