fcaviggia / hardened-centos7-kickstart

DVD embedded Kickstart for CentOS 7 utilizing SCAP Security Guide (SSG) as a hardening script.
Other
158 stars 58 forks source link

Some BIOS/UEFI show unmodified Centos installer boot menu #11

Closed ajd394 closed 7 years ago

ajd394 commented 7 years ago

When i boot in BIOS mode i see the Hardened install menu but booting in UEFI mode displays the regular Centos 7 install menu.

ajd394 commented 7 years ago

someone having a similar problem (no solution discussed ) https://www.centos.org/forums/viewtopic.php?t=48639

symgryph commented 7 years ago

This seems to have been fixed. You DO have to run the installer from its default directory, however. Seems like running it outside of that (I just created a script that 'cd's' to the directory. Otherwise seems likes it doesn't work.

ajd394 commented 7 years ago

@symgryph Hey I'm having trouble understanding how you are able to make it work. I cloned this repo and executed createiso.sh after "cd hardened-centos7-kickstart". then dd the hardened iso to a usb and booted to it in UEFI mode. at that point i saw the regular Centos 7 install menu.

fcaviggia commented 7 years ago

Have you tried recently? I believe this issue has been fixed.

ajd394 commented 7 years ago

I used dd to make a flash drive and it didn't boot to the hardened installer but then I made an old fashioned CD out of it and it worked fine. Not sure if that is a bug or not. Could have been and issue with the bios firmware on the system I was using. On Sat, May 13, 2017 at 2:51 PM Frank Caviggia notifications@github.com wrote:

Have you tried recently? I believe this issue has been fixed.

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub https://github.com/fcaviggia/hardened-centos7-kickstart/issues/11#issuecomment-301267443, or mute the thread https://github.com/notifications/unsubscribe-auth/AFJ3CrUi0ZgnEd2cWSrHdij4gtXEACT4ks5r5fvBgaJpZM4M_MkW .

fcaviggia commented 7 years ago

Okay, I'll do some testing - but I'm going to close this issue for now.

symgryph commented 7 years ago

You probably need to set the bios to emulate a cd 💿.

Thomas J Munn

On May 13, 2017, at 17:17, Frank Caviggia notifications@github.com wrote:

Closed #11.

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub, or mute the thread.

ajd394 commented 7 years ago

I also found that virtualbox doesn't see the hardened boot menu but VMware fusion does. Basically the type of bios makes a big difference. I see this as an issue still.

fcaviggia commented 7 years ago

I can check virtualbox here in a bit - I've only tested it in KVM and VMware.

-Frank

On Fri, May 26, 2017 at 10:09 AM, Andrew notifications@github.com wrote:

I also found that virtualbox doesn't see the hardened boot menu but VMware fusion does. Basically the type of bios makes a big difference. I see this as an issue still.

— You are receiving this because you modified the open/close state. Reply to this email directly, view it on GitHub https://github.com/fcaviggia/hardened-centos7-kickstart/issues/11#issuecomment-304291794, or mute the thread https://github.com/notifications/unsubscribe-auth/AF0Ng-VLDTQppauWHGzGQQD7Pt4W4Lzqks5r9t0WgaJpZM4M_MkW .

ajd394 commented 7 years ago

@fcaviggia in the virtualbox settings i tried checking the EFI mode to no avail.

fcaviggia commented 7 years ago

Latest version - looks good to me - CentOS 7.3 (1611) booting with UEFI on VirtualBox v5.1.22 - only configuration item was selection EFI in the System Menu - Installed just fine. I've also tested with KVM (on Fedora 25) and VMware ESXi 6.5

On Fri, May 26, 2017 at 10:28 AM, Andrew notifications@github.com wrote:

@fcaviggia https://github.com/fcaviggia in the virtualbox settings i tried checking the EFI mode to no avail.

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub https://github.com/fcaviggia/hardened-centos7-kickstart/issues/11#issuecomment-304297485, or mute the thread https://github.com/notifications/unsubscribe-auth/AF0Ng7iL8rZ5wE_y2ja0FSPzdGrWeRm8ks5r9uGCgaJpZM4M_MkW .