STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must enforce password complexity by requiring that at least one lowercase character be used.

DISA Rule

SV-266089r1024622_rule

Vulnerability Number

V-266089

Group Title

SRG-APP-000167-NDM-000255

Rule Version

F5BI-DM-300051

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Under "Password Policy" set "Secure Password Enforcement" to "Enabled".
5. Under "Required Characters" set "Lowercase" to at least 1.
6. Click "Update".

From the BIG-IP console, type the following commands:

tmsh modify auth password-policy required-lowercase 1
tmsh save sys config

Check Contents

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Verify that "Secure Password Enforcement" is set to "Enabled".
5. Verify under "Required Characters" that "Lowercase" is set to at least 1.

From the BIG-IP console, type the following command:

tmsh list auth password-policy required-lowercase

Note: Verify the value is set to at least 1.

If the BIG-IP appliance is not configured to enforce password complexity by requiring that at least one lowercase character be used, this is a finding.

Vulnerability Number

V-266089

Documentable

False

Rule Version

F5BI-DM-300051

Severity Override Guidance

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Verify that "Secure Password Enforcement" is set to "Enabled".
5. Verify under "Required Characters" that "Lowercase" is set to at least 1.

From the BIG-IP console, type the following command:

tmsh list auth password-policy required-lowercase

Note: Verify the value is set to at least 1.

If the BIG-IP appliance is not configured to enforce password complexity by requiring that at least one lowercase character be used, this is a finding.

Check Content Reference

M

Target Key

5639