Gentoo Archives: gentoo-user

From: "Jesús Guerrero" <6thpink@×××××.es>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] grub passwords - how do I limit OS selection?
Date: Sun, 30 Jul 2006 19:23:58
Message-Id: 200607302117.52428.6thpink@terra.es
In Reply to: [gentoo-user] grub passwords - how do I limit OS selection? by Mark Knecht
1 El Domingo, 30 de Julio de 2006 16:09, Mark Knecht escribió:
2 > Hi,
3 > I would like to limit OS selection at boot time. The machine has
4 > Gentoo and Windows. Gentoo *must* be the booted OS unless a password
5 > is entered. I have tried the password feature in grub but it does not
6 > implement this feature. It implements changing boot time kernel
7 > options, but not OS choice as far as I can tell.
8 >
9 > I also tried adding the hiddenmenu option in grub but it seems that
10 > with hiddenmenu turned on grub never accepts a password.
11 >
12 > Is there a way to implement what I need? If you can provide an
13 > example that would be great.
14 >
15 > NOTE: I currently do this be editing the grub file itself but I'm
16 > looking for something more sophisticated since I'd like my wife to be
17 > able to boot Windows but not my son.
18 >
19 > Thanks all,
20 > Mark
21
22 Grub cant do that.
23
24 It can protect with passwords the menu entries, to prevent anyone from editing
25 them (to boot with an alternate kernel, from another root, in any other
26 runlevel or stuff like that). But it cant protect -as far as I can tell- the
27 entries one by one.
28
29 You want to be able to boot into linux at any given momment, and grub to ask
30 you for a password if you hit enter when the Windows entry is selected. If
31 that affirmation is correct, then grub cant do that for what I can tell.
32
33 I use md5 pass in grub, but it just prevent someone from editing the grub
34 stuff and using a different root or kernel line to boot from.
35
36 You best bet is to use WinXp, 2k, or any other version of windows that can be
37 hardened a bit. Just put a password in all the windows accounts, and do not
38 give any password to your son. This way, you son will be able to see the
39 Winxp login screen, but he will not be able to enter without a password.
40
41 If your son is smart enough, anyway, the passwords are nothing (he can always
42 boot from the linux partition, locate the keys, and decipher them with jack
43 or something similar, nt passwords are not hard to beat, and a fast search in
44 the net will reveal all that you need to know to do so). So, in which regards
45 children, the best bet is to cut the physicall access to the box.
46
47 --
48 gentoo-user@g.o mailing list