Solved

Linux VM hardenings : any concern

Posted on 2014-10-20
12
117 Views
Last Modified: 2014-11-03
If we perform the following 3 hardenings for our tenant/customer Linux VM,
will it affect any sysadmin operation (say if password is forgotten, can't recover
back the VM or we can help apply patches for the tenant) and break any apps ?
 

CIS 1.5.3 Set Boot Loader Password
No boot loader password set. Can we set boot loader password and any concern ?

 

CIS 1.5.4 Require Authentication for Single-User Mode
No single-user mode password set. Can we set password protection when boot to single user mode and any concern ?

 

CIS 1.5.5 Disable Interactive Boot
Interactive Boot is enabled. Any concern to disable interactive boot ?
0
Comment
Question by:sunhux
  • 6
  • 6
12 Comments
 
LVL 61

Expert Comment

by:gheist
ID: 40392818
No, just that it is a pain to run to office to enter boot passwords mid Xmas holiday....
0
 

Author Comment

by:sunhux
ID: 40393605
But the tenant can't access our vCenter so wouldn't that make any
difference if we set the password?  

As far as I know the access of console via vCenter is only
restricted to us, the cloud provider only
0
 
LVL 61

Assisted Solution

by:gheist
gheist earned 500 total points
ID: 40393649
Then it makes even less sense... You will get virtual machines that dont boot by themselves, and you need to enter password on them. (Probably possible if you have 10 VMs, but when it gets to 100 you get crazy half way...
0
 

Author Comment

by:sunhux
ID: 40394431
So we (the cloud provider) has to advise the tenants not to set
passwords, else whenever the VM reboots, someone at our (the
cloud provider) end needs to be around to enter the console
password(s) at vCenter, right?
0
 

Author Comment

by:sunhux
ID: 40394433
Among the 3, which ones would you recommend not to set password
so as not to cause this inconvenience whenever a VM reboots, it will
not boot up by itself unless the password(s) is entered?
0
 

Author Comment

by:sunhux
ID: 40394707
More specifically, I need clarifications on:

a) Set Boot Loader Password:
    if this password is set, when tenant reboot (shutdown -r)
    their VM each time, will it prompt for the bootloader
    password at console?  If so, is there any way the tenant,
    could still get their VM booted up if they have no access
    to vCenter's console?

b) Require Authentication for Single-User Mode
    Does Linux allow ssh access while in single-user mode &
    can this 'single-user mode password' be entered via an
    ssh session (without access to console), assuming certain
    'terminal' service is started up / running while in single
    user mode

c) Disable Interactive Boot:
    what's the general consensus on this? Disable or enable?
    Our corporate hardening guide does not mention this item.
    So if the tenant wishes to boot up step by step (ie pausing
    at each startup script), they can't do it?

Pls add on any other operational impact if the above 3 items
are hardened.
0
Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

 
LVL 61

Assisted Solution

by:gheist
gheist earned 500 total points
ID: 40394708
It is meant to protect physical access. With you entering passwords... there is almost no purpose. If your custometr has formal requirement for something that should be applied to protecting your infrastructure and by extension protecting theirs...
0
 

Author Comment

by:sunhux
ID: 40394751
For item (b), is there any possibility of getting the network services
& sshd started at runlevel 1 (ie single user mode)?  Any other
services need to be started to be able to ssh in to the VM while
in single-user mode & to be able to enter the password prompted
when prompted to enter at runlevel 1?
0
 
LVL 61

Expert Comment

by:gheist
ID: 40395664
b) those services are started AFTER password is entered...
0
 
LVL 61

Assisted Solution

by:gheist
gheist earned 500 total points
ID: 40395666
PS loudest attacks of modern times like heartbleed just dumped apache's memory space and all raw host keys, protecting boot loader was irrelevant.
0
 

Author Comment

by:sunhux
ID: 40396387
Can you reply directly / specifically to the earlier 3 questions:

 I need clarifications on:

a) Set Boot Loader Password:
    if this password is set, when tenant reboot (shutdown -r)
    their VM each time, will it prompt for the bootloader
    password at console?  If so, is there any way the tenant,
    could still get their VM booted up if they have no access
    to vCenter's console?

b) Require Authentication for Single-User Mode
    Does Linux allow ssh access while in single-user mode &
    can this 'single-user mode password' be entered via an
    ssh session (without access to console), assuming certain
    'terminal' service is started up / running while in single
    user mode

c) Disable Interactive Boot:
    what's the general consensus on this? Disable or enable?
    Our corporate hardening guide does not mention this item.
    So if the tenant wishes to boot up step by step (ie pausing
    at each startup script), they can't do it?

Pls add on any other operational impact if the above 3 items
are hardened.
0
 
LVL 61

Accepted Solution

by:
gheist earned 500 total points
ID: 40396535
None of them is relevant to physically securing virtual machine.
Outer virtualisation product has to be secured instead.

assuming attacker gets to VM's management interfaces (more or less equivalent getting to physical machine) he can bypass named protections:
a) by booting off his own livecd
b) by modifying inittab
c) once in single mode one can start stop single service as they choose
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Join & Write a Comment

In this article, I will show you HOW TO: Suppress Configuration Issues and Warnings Alert displayed in Summary status for ESXi 6.5 after enabling SSH or ESXi Shell.
In this article, I will show you HOW TO: Install VMware Tools for Windows on a VMware Windows virtual machine on a VMware vSphere Hypervisor 6.5 (ESXi 6.5) Host Server, using the VMware Host Client. The virtual machine has Windows Server 2016 instal…
Teach the user how to use vSphere Update Manager to update the VMware Tools and virtual machine hardware version Open vSphere Client: Review manual processes for updating VMware Tools and virtual hardware versions: Create a new baseline group in vSp…
This video shows you how to use a vSphere client to connect to your ESX host as the root user. Demonstrates the basic connection of bypassing certification set up. Demonstrates how to access the traditional view to begin managing your virtual mac…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now