STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must enforce a minimum 15-character password length.

DISA Rule

SV-266087r1024891_rule

Vulnerability Number

V-266087

Group Title

SRG-APP-000164-NDM-000252

Rule Version

F5BI-DM-300049

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Under "Password Policy" set "Secure Password Enforcement" to "Enabled".
5. Configure "Minimum Length" to 15.
6. Click "Update".

From the BIG-IP console, type the following command(s):

tmsh modify auth password-policy minimum-length 15
tmsh save sys config

Check Contents

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Verify that "Secure Password Enforcement" is set to "Enabled".
5. Verify that "Minimum Length" is set to at least 15.

From the BIG-IP console, type the following command(s):

tmsh list auth password-policy minimum-length

Note: Verify the value is set to at least 15.

If the BIG-IP appliance is not configured to enforce a minimum 15-character password length, this is a finding.

Vulnerability Number

V-266087

Documentable

False

Rule Version

F5BI-DM-300049

Severity Override Guidance

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Verify that "Secure Password Enforcement" is set to "Enabled".
5. Verify that "Minimum Length" is set to at least 15.

From the BIG-IP console, type the following command(s):

tmsh list auth password-policy minimum-length

Note: Verify the value is set to at least 15.

If the BIG-IP appliance is not configured to enforce a minimum 15-character password length, this is a finding.

Check Content Reference

M

Target Key

5639