Sun ULTRA 20 and BIOS password security hole

From: Olaf Hopp (Olaf.Hopp@atis.uka.de)
Date: Mon Feb 27 2006 - 02:33:33 EST


Dear Collegues,

is anybody running the new Opteron Workstations Ultra20 in an open
classroom ? You can lock down the access to the BIOS via a BIOS password.
But when the system boots it still allows you to press <F8>-Key and
select a boot device - and (that's the problem) it allows you
to boot from that device WITHOUT entering the BIOS password.
This is even true when you disable booting from CD/DVD within
the BIOS.
So pressing F8 lets you always boot from any device without password.
And this makes it impossilble for me to put them into an open classroom,
where any student can reach control over the maschine with a stupid
KNOPPIX-CD.

Did I overlooked something in the BIOS ?
I can't believe that SUN delivers a maschine with such a security hole.

Hardware: SUN Ultra20
BIOS-Version: 2.1.7 (seems to be the latest one)

Regards,

Olaf

-- 
==============================================================================
     __0
   _-\<,_     Dipl.-Geophys. Olaf Hopp
  (_)/ (_)    ATIS - Abteilung Technische Infrastruktur
University of Karlsruhe          EMail: Olaf.Hopp@atis.uka.de
Faculty of Computer Science      WWW  : http://www.atis.uka.de
Building 50.34 Room-No. 009
Am Fasanengarten 5               Fon  : +49 (721) 608-3973
D-76131 Karlsruhe / Germany      Fax  : +49 (721) 608-6699
==============================================================================
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers


This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 23:39:07 EDT