Re: Root boot/mount Password?



On Sat, Jul 26, 2008 at 01:53:27PM -0400, Chuck Robey wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

DSA - JCR wrote:
Hi all

FreeBSD 6.2

I would like to put a password when booting/mounting mi Freebsd box.
is it possible? How?

What I want is that if the system is rebooted or shutdown, somebody must
enter a password to boot and/or mounting "/"

is for protecting the system from unauthorized users

A couple of items here. The first is a long known rule of security, which is,
if an attacker has physical access to the console, then the game is up, you
can't protect it any more.

You cannot protect the machine if an attacker has physical access. But
you _can_ protect your data by encrypting it. Hence my advice to use geli(8).

Roland
--
R.F.Smith http://www.xs4all.nl/~rsmith/
[plain text _non-HTML_ PGP/GnuPG encrypted/signed email much appreciated]
pgp: 1A2B 477F 9970 BA3C 2914 B7CE 1277 EFB0 C321 A725 (KeyID: C321A725)

Attachment: pgpkWFsn8wZaT.pgp
Description: PGP signature



Relevant Pages

  • Re: Protection from Hackers
    ... physical access to the system. ... You protect against this sort of attack by ... The bottom line is that once your attacker has physical access, ... > Administrator account, but this program showed ALL accounts and you ...
    (microsoft.public.win2000.security)
  • Re: protecting my FreeBSD system
    ... USB disk in which I trap almost all signals. ... FreeBSD gives you all the tools you need to build a very secure system, but it is up to you. ... what you want to protect, from whom, what kind of access they have to the machine. ... A strong root password is good, but not of much use if someone can walk to the machine and reboot it to single user mode, or even worse get the disk and run. ...
    (freebsd-questions)
  • Re: protecting my FreeBSD system
    ... system (FreeBSD 6.2) in order to not permit a user to enter as root. ... Note that nothing short of disk encryption can protect the machine if ... Security is a never-ending road, ... that you're using umass) give that group read/write rights on the da ...
    (freebsd-questions)
  • Protecting against kernel NULL-pointer derefs
    ... Given the amount of NULL-pointer dereference vulnerabilities in the ... FreeBSD kernel that have been discovered of late, ... at a way to generically protect against the code execution possibilities ... How do you feel about disallowing such mappings to protect against ...
    (FreeBSD-Security)
  • Re: Root boot/mount Password?
    ... I would like to put a password when booting/mounting mi Freebsd box. ... can't protect it any more. ... respect that rule about an attacker with physical access to the console: ... Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org ...
    (freebsd-questions)