STIGQter STIGQter: STIG Summary: SUSE Linux Enterprise Micro (SLEM) 5 Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 01 Apr 2026:

SLEM 5 must require the change of at least eight of the total number of characters when passwords are changed.

DISA Rule

SV-261383r996580_rule

Vulnerability Number

V-261383

Group Title

SRG-OS-000072-GPOS-00040

Rule Version

SLEM-05-611040

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure SLEM 5 to require at least eight characters be changed between the old and new passwords during a password change with the following command:

Edit "/etc/pam.d/common-password" and edit the line containing "pam_cracklib.so" to contain the option "difok=8" after the third column.

Check Contents

Verify SLEM 5 requires at least eight characters be changed between the old and new passwords during a password change with the following command:

> grep pam_cracklib.so /etc/pam.d/common-password
password requisite pam_cracklib.so difok=8

If the value for "difok" is not "8" or greater, if "difok" is missing from the line, the second column value different from "requisite", the line is commented out, or the line is missing, this is a finding.

Vulnerability Number

V-261383

Documentable

False

Rule Version

SLEM-05-611040

Severity Override Guidance

Verify SLEM 5 requires at least eight characters be changed between the old and new passwords during a password change with the following command:

> grep pam_cracklib.so /etc/pam.d/common-password
password requisite pam_cracklib.so difok=8

If the value for "difok" is not "8" or greater, if "difok" is missing from the line, the second column value different from "requisite", the line is commented out, or the line is missing, this is a finding.

Check Content Reference

M

Target Key

5596