BIOS hardening for RSA Authentication Manager 8.x
2 years ago
Originally Published: 2015-07-07
Article Number
000053697
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition:  8.x
Issue
Chapter 2 (page 36) of the RSA Authentication Manager 8.1 Security Configuration Guide (Revision 2) covers BIOS hardening; however, it does not offer the steps to change the BIOS password.
Resolution
To protect access to the BIOS, RSA recommends that administrators change the preconfigured BIOS password to a strong password of their choice.
 

Changing the BIOS password requires a reboot of the RSA SecurID Appliance so plan accordingly for an outage.


Steps

  1. Log in to the RSA SecurID Appliance with the rsaadmin account at the local console and enter the password for rsaadmin when prompted.  The password for this account was set up during the deployment of the SecurID Appliance and is unknown to RSA.
  2. To reboot the RSA SecurID Appliance at the command line, use the command sudo reboot.
  3. On startup, the SecurID Appliance local console initially shows the RAID Controller BIOS version and RAID configuration information, as shown here:
User-added image
  1. On the next screen, the administrator is given the option to press F2 to enter the setup.
User-added image
  1. Press F2 to enter the setup.
  2. You are prompted to enter a password.  For example:
User-added image
  1. After the BIOS password is entered, the BIOS menu is shown:
User-added image 
  1. ​Use the arrow keys on the keyboard to navigate the BIOS menu and select Security.  For example:
User-added image
  1. Select Set Administrator Password.
  2. Enter the current password for the BIOS.
User-added image
  1. Create a new BIOS password:
User-added image
  1. Confirm the new BIOS password:
User-added image
 
You may get the following warning if the password is not considered to be strong enough; however, the weak password is still accepted.
 
User-added image

Use a strong password to ensure security.  Store the new BIOS password in a secure place.

  1. After the BIOS password change, navigate the BIOS menu and select Exit.  For example:
User-added image
  1. Select Save Changes and Exit.
  2. When prompted select Yes to save the configuration and exit.
User-added image
  1. The SecurID Appliance will then go through a reboot sequence.
Notes