SV-258094r1045187_rule
V-258094
SRG-OS-000480-GPOS-00227
RHEL-09-611025
CAT I
10
If PAM is managed with authselect, use the following command to remove instances of "nullok":
$ sudo authselect enable-feature without-nullok
Otherwise, remove any instances of the "nullok" option in the "/etc/pam.d/password-auth" and "/etc/pam.d/system-auth" files to prevent logons with empty passwords.
Note: Manual changes to the listed file may be overwritten by the "authselect" program.
Verify that null passwords cannot be used with the following command:
$ sudo grep -i nullok /etc/pam.d/system-auth /etc/pam.d/password-auth
If output is produced, this is a finding.
If the system administrator (SA) can demonstrate that the required configuration is contained in a PAM configuration file included or substacked from the system-auth file, this is not a finding.
V-258094
False
RHEL-09-611025
Verify that null passwords cannot be used with the following command:
$ sudo grep -i nullok /etc/pam.d/system-auth /etc/pam.d/password-auth
If output is produced, this is a finding.
If the system administrator (SA) can demonstrate that the required configuration is contained in a PAM configuration file included or substacked from the system-auth file, this is not a finding.
M
5551