To protect access to the BIOS, RSA recommends that administrators change the preconfigured BIOS password to a strong password of their choice.
Changing the BIOS password requires a reboot of the RSA SecurID Appliance so plan accordingly for an outage.
Steps
Log in to the RSA SecurID Appliance with the rsaadmin account at the local console and enter the password for rsaadmin when prompted. The password for this account was set up during the deployment of the SecurID Appliance and is unknown to RSA.
To reboot the RSA SecurID Appliance at the command line, use the command sudo reboot.
On startup, the SecurID Appliance local console initially shows the RAID Controller BIOS version and RAID configuration information, as shown here:
Image description
On the next screen, the administrator is given the option to pressF2 to enter the setup.
Image description
Press F2 to enter the setup.
You are prompted to enter a password. For example:
Image description
After the BIOS password is entered, the BIOS menu is shown:
Image description
Use the arrow keys on the keyboard to navigate the BIOS menu and select Security. For example:
Image description
Select Set Administrator Password.
Enter the current password for the BIOS.
Image description
Create a new BIOS password:
Image description
Confirm the new BIOS password:
Image description
You may get the following warning if the password is not considered to be strong enough; however, the weak password is still accepted.
Image description
Use a strong password to ensure security. Store the new BIOS password in a secure place.
After the BIOS password change, navigate the BIOS menu and select Exit. For example:
Image description
Select Save Changes and Exit.
When prompted select Yes to save the configuration and exit.
Image description
The SecurID Appliance will then go through a reboot sequence.