SV-266090r1024623_rule
V-266090
SRG-APP-000168-NDM-000256
F5BI-DM-300052
CAT II
10
From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Under "Password Policy" set "Secure Password Enforcement" to "Enabled".
5. Under "Required Characters" set "Numeric" to at least 1.
6. Click "Update".
From the BIG-IP console, type the following command:
tmsh modify auth password-policy required-numeric 1
tmsh save sys config
From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Verify that "Secure Password Enforcement" is set to "Enabled".
5. Verify under "Required Characters" that "Numeric" is set to at least 1.
From the BIG-IP console, type the following command:
tmsh list auth password-policy required-numeric
Note: Verify the value is set to at least 1.
If the BIG-IP appliance is not configured to enforce password complexity by requiring that at least one numeric character be used, this is a finding.
V-266090
False
F5BI-DM-300052
From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Verify that "Secure Password Enforcement" is set to "Enabled".
5. Verify under "Required Characters" that "Numeric" is set to at least 1.
From the BIG-IP console, type the following command:
tmsh list auth password-policy required-numeric
Note: Verify the value is set to at least 1.
If the BIG-IP appliance is not configured to enforce password complexity by requiring that at least one numeric character be used, this is a finding.
M
5639