STIGQter STIGQter: STIG Summary: Oracle Linux 8 Security Technical Implementation Guide Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

OL 8 systems, version 8.4 and above, must ensure the password complexity module is configured for three retries or less.

DISA Rule

SV-252660r991589_rule

Vulnerability Number

V-252660

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

OL08-00-020104

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the operating system to limit the "pwquality" retry option to 3.

Add the following line to the "/etc/security/pwquality.conf" file(or modify the line to have the required value):

retry = 3

Remove any configurations that conflict with the above value.

Check Contents

Note: This requirement applies to OL versions 8.4 or newer. If the system is OL below version 8.4, this requirement is not applicable.

Verify the operating system is configured to limit the "pwquality" retry option to 3.

Check for the use of the "pwquality" retry option with the following command:

$ sudo grep -r retry /etc/security/pwquality.conf*

/etc/security/pwquality.conf:retry = 3

If the value of "retry" is set to "0" or greater than "3", is commented out or missing, this is a finding.

If conflicting results are returned, this is a finding.

Check for the use of the "pwquality" retry option in the system-auth and password-auth files with the following command:

$ sudo grep pwquality /etc/pam.d/system-auth /etc/pam.d/password-auth | grep retry

If the command returns any results, this is a finding.

Vulnerability Number

V-252660

Documentable

False

Rule Version

OL08-00-020104

Severity Override Guidance

Note: This requirement applies to OL versions 8.4 or newer. If the system is OL below version 8.4, this requirement is not applicable.

Verify the operating system is configured to limit the "pwquality" retry option to 3.

Check for the use of the "pwquality" retry option with the following command:

$ sudo grep -r retry /etc/security/pwquality.conf*

/etc/security/pwquality.conf:retry = 3

If the value of "retry" is set to "0" or greater than "3", is commented out or missing, this is a finding.

If conflicting results are returned, this is a finding.

Check for the use of the "pwquality" retry option in the system-auth and password-auth files with the following command:

$ sudo grep pwquality /etc/pam.d/system-auth /etc/pam.d/password-auth | grep retry

If the command returns any results, this is a finding.

Check Content Reference

M

Target Key

5416