SV-258814r1015939_rule
V-258814
SRG-OS-000069-GPOS-00037
PHTN-40-000035
CAT II
10
Navigate to and open:
/etc/pam.d/system-password
Configure the pam_pwquality.so line to have the "ucredit" option set to "-1" as follows:
password requisite pam_pwquality.so dcredit=-1 ucredit=-1 lcredit=-1 ocredit=-1 minlen=15 difok=8 enforce_for_root dictcheck=1
Note: On vCenter appliances, the equivalent file must be edited under "/etc/applmgmt/appliance", if one exists, for the changes to persist after a reboot.
At the command line, run the following command to verify at least one uppercase character be used:
# grep '^password.*pam_pwquality.so' /etc/pam.d/system-password
Example result:
password requisite pam_pwquality.so dcredit=-1 ucredit=-1 lcredit=-1 ocredit=-1 minlen=15 difok=8 enforce_for_root dictcheck=1
If the "ucredit" option is not < 0, is missing or commented out, this is a finding.
V-258814
False
PHTN-40-000035
At the command line, run the following command to verify at least one uppercase character be used:
# grep '^password.*pam_pwquality.so' /etc/pam.d/system-password
Example result:
password requisite pam_pwquality.so dcredit=-1 ucredit=-1 lcredit=-1 ocredit=-1 minlen=15 difok=8 enforce_for_root dictcheck=1
If the "ucredit" option is not < 0, is missing or commented out, this is a finding.
M
5569