SV-266088r1024894_rule
V-266088
SRG-APP-000166-NDM-000254
F5BI-DM-300050
CAT II
10
From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Under "Password Policy" set "Secure Password Enforcement" to "Enabled".
5. Under "Required Characters" set "Uppercase" to at least 1.
6. Click "Update".
From the BIG-IP console, type the following command(s):
tmsh modify auth password-policy required-uppercase 1
tmsh save sys config
From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Verify that "Secure Password Enforcement" is set to "Enabled".
5. Verify under "Required Characters" that "Uppercase" is set to at least 1.
From the BIG-IP console, type the following command(s):
tmsh list auth password-policy required-uppercase
Note: Verify the value is set to at least 1.
If the BIG-IP appliance is not configured to enforce password complexity by requiring that at least one uppercase character be used, this is a finding.
V-266088
False
F5BI-DM-300050
From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Verify that "Secure Password Enforcement" is set to "Enabled".
5. Verify under "Required Characters" that "Uppercase" is set to at least 1.
From the BIG-IP console, type the following command(s):
tmsh list auth password-policy required-uppercase
Note: Verify the value is set to at least 1.
If the BIG-IP appliance is not configured to enforce password complexity by requiring that at least one uppercase character be used, this is a finding.
M
5639