Trusted Solaris Installation and Configuration

How to Protect Machine Hardware

For security, access to the PROM should also be protected with a password.

SPARC: To Set the PROM Mode and Password

    As root, label ADMIN_LOW, in the profile shell, enter the PROM security mode.

    1. Choose the value command or full (see the eeprom(1M) man page for more details).

      You are prompted to enter and confirm the PROM password.


      # eeprom security-mode=command
      
      Changing PROM password:
      	New password: password
      	Retype new password: password
      

    2. If you are not prompted to enter a PROM password, the workstation already has a PROM password. To change it, run the command:


      # eeprom security-password=Return
      Changing PROM password:
      New password: password
      Retype new password: password
      

    The new PROM security mode and password are in effect immediately, but are most likely to be noticed at the next boot.


    Caution - Caution -

    Do not forget this password. The hardware is unusable without it.


    For more information on PROM values that you can set, see OpenBoot 2.x Command Reference Manual or OpenBoot 3.x Command Reference Manual.

IA: To Protect the BIOS

On Intel architecture, the equivalent to protecting the PROM is to protect the BIOS.

    Refer to your machine's manuals for how to protect the BIOS.