Create and Safely Install a GRUB PBKDF2 Password Hash
You will finish with a GRUB PBKDF2 password hash that can be used by a GRUB configuration, while keeping the clear-text password out of the command line and shell history. The examples use GRUB 2.12-1ubuntu7.3 from the grub-common package, as installed on this machine.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about ten minutes. You need a local shell, grub-mkpasswd-pbkdf2, and a root shell or sudo only for the later configuration step. Generating the hash does not change the boot loader. Editing /boot/grub/grub.cfg can affect boot access, so keep a second administrative session open and a tested recovery path available.
1. Check the installed tool
Start with two read-only checks. They do not need elevated privileges:
$ grub-mkpasswd-pbkdf2 --version
grub-mkpasswd-pbkdf2 (GRUB) 2.12-1ubuntu7.3
$ dpkg-query -W -f='${Package} ${Version}\n' grub-common
grub-common 2.12-1ubuntu7.3
Your package revision may differ. The important checkpoint is that the command is present and you know which installed GRUB build supplied it.
2. Generate the hash interactively
Run the command without putting a password in the command line:
$ grub-mkpasswd-pbkdf2
Enter password:
Reenter password:
PBKDF2 hash of your password is grub.pbkdf2.sha512.10000.SALT.HASH
The password is entered twice. Nothing useful should be printed in place of the password itself. Copy only the complete value beginning grub.pbkdf2.sha512., from the word grub through the final character of the hash. Do not copy the explanatory sentence around it.
On the installed version, the default output observed here uses SHA-512 and 10,000 PBKDF2 iterations. The salt and derived hash are generated values, so they will differ on every successful run. Treat the resulting string as sensitive configuration: it cannot be used to recover the original password, but it does allow GRUB to verify guesses.
Checkpoint: save the copied value in a protected temporary note, or keep the terminal visible while you complete the configuration. Do not paste it into a public issue, chat room or shell command recorded in history.
3. Understand the tunable options before changing them
The manual exposes three numeric options:
--iteration-count=NUMselects the number of PBKDF2 iterations.--buflen=NUMselects the length of the generated hash.--salt=NUMselects the length of the salt.
For a normal workstation, the default command is the least surprising choice. More iterations increase the work required for each password check, but also increase boot-time checking cost. A shorter salt or derived value weakens the margin available against guessing. Do not copy tuning values from an unrelated host without recording why they were chosen and testing that the target GRUB build accepts the result.
If you need a deliberately explicit, low-cost test hash, use options that the installed command accepts:
$ grub-mkpasswd-pbkdf2 --iteration-count=1000 --salt=8 --buflen=64
Enter password:
Reenter password:
PBKDF2 hash of your password is grub.pbkdf2.sha512.1000.SALT.HASH
This example is useful for checking syntax, not for protecting a real boot menu. For production, generate a fresh hash with the default command unless your security policy says otherwise. The long options have short forms, -c, -s and -l, but full names are easier to audit in notes and scripts.
4. Put the hash in GRUB configuration carefully
Generating a hash alone does not enable GRUB authentication. The hash must be referenced by GRUB configuration, normally through a custom configuration fragment or the distribution's GRUB configuration workflow. The exact user declaration and menu restrictions depend on how your system manages /etc/grub.d and /etc/default/grub; do not paste a guessed stanza into a production boot configuration.
Before making a privileged change, make a recoverable copy of the configuration file you intend to edit:
$ sudo cp --preserve=all /etc/grub.d/40_custom /etc/grub.d/40_custom.bak
$ sudoedit /etc/grub.d/40_custom
Place the hash only where the GRUB syntax for your installation expects it. Keep the file readable by root and avoid putting the clear-text password in it. The backup is an undo point: if the generated configuration is wrong, restore it with sudo cp --preserve=all /etc/grub.d/40_custom.bak /etc/grub.d/40_custom, then regenerate the configuration again.
Do not edit generated /boot/grub/grub.cfg as your first choice. A later package update or configuration rebuild can replace that file. If your distribution's documented workflow requires a different file, follow that workflow and preserve an equivalent backup first.
5. Rebuild and inspect before rebooting
Once the configuration fragment is correct, regenerate GRUB using the command your distribution provides. On Ubuntu systems this is commonly:
$ sudo update-grub
That command is outside grub-mkpasswd-pbkdf2, and its output depends on the installed scripts. Treat any error as a stop sign. Do not reboot until the rebuild completes successfully and the generated file contains the intended GRUB user or hash reference:
$ sudo grep -n 'grub.pbkdf2.sha512' /boot/grub/grub.cfg
123: set superusers="GRUB_ADMIN"
124: password_pbkdf2 GRUB_ADMIN grub.pbkdf2.sha512.10000.SALT.HASH
The line number and generated values vary. If the search returns nothing, the hash was not incorporated; check the source fragment and the rebuild output rather than assuming authentication is active.
6. Test the boundary without losing access
Reboot only when you have confirmed that you know the new password and that console or provider recovery is available. At the GRUB menu, check that the expected authentication prompt appears and that the password works. If the menu is inaccessible, use the machine's documented console or recovery method and restore the backup configuration from a root shell. Do not repeatedly guess at the boot menu if the account or stanza is wrong.
A successful grub-mkpasswd-pbkdf2 exit proves that a hash was generated. It does not prove that GRUB will load it, that the user name matches, or that every menu entry is protected. Those are configuration and policy checks performed separately.
Done means
- The installed GRUB version and package were checked.
- The password was entered interactively and never placed in a command argument.
- The complete
grub.pbkdf2.sha512...value was copied without exposing the clear-text password. - Any numeric tuning was deliberate, documented and tested, rather than copied blindly.
- A backup exists before privileged GRUB configuration changes.
- The regenerated configuration contains the intended hash reference, and recovery remains available before reboot.