Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
How to restrict single user mode?
« previous
next »
Print
Pages: [
1
]
Author
Topic: How to restrict single user mode? (Read 1029 times)
nitish.patel
Newbie
Posts: 36
Karma: 0
How to restrict single user mode?
«
on:
September 15, 2023, 09:08:51 am »
I am trying to restrict the user to login single user mode, so that they cannot change the root password, in OPNsense firewall.
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: How to restrict single user mode?
«
Reply #1 on:
September 15, 2023, 09:25:28 am »
So what's your threat model?
Cheers,
Franco
Logged
nitish.patel
Newbie
Posts: 36
Karma: 0
Re: How to restrict single user mode?
«
Reply #2 on:
September 15, 2023, 09:33:10 am »
Currently I am using OPNSense 23.7, user's are abled to change the root password using the single user mode, I want to prevent this.
Cheers,
Nitish
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: How to restrict single user mode?
«
Reply #3 on:
September 15, 2023, 09:46:46 am »
I'm not sure you know how this works.
In order to boot single user mode and modify things the user needs to be in front of the physical hardware with a keyboard and monitor attached. In case of a VM the user needs console access through the hypervisor.
I'm doubting both things are issues for you. And if you are worried about physical access you can lock the room the hardware is in.
Cheers,
Franco
Logged
Patrick M. Hausen
Hero Member
Posts: 6810
Karma: 572
Re: How to restrict single user mode?
«
Reply #4 on:
September 15, 2023, 12:35:33 pm »
You can remove the 'secure' keyword from the console tty in '/etc/ttys'. It will then be necessary to provide the current root password to login to single user mode.
Anyway with physical access anyone could boot a live system from e.g. a USB drive, mount the root filesystem or ZFS pool and work from there.
So as @franco wrote, the only real option is to local the machine away.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
How to restrict single user mode?