STIGQter STIGQter: STIG Summary: Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide Version: 1 Release: 7 Benchmark Date: 01 Jul 2026:

AlmaLinux OS 9 must ensure the password complexity module in the system-auth file is configured for three retries or less.

DISA Rule

SV-269387r1050270_rule

Vulnerability Number

V-269387

Group Title

SRG-OS-000069-GPOS-00037

Rule Version

ALMA-09-035990

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure AlmaLinux OS 9 to limit the "pwquality" retry option to "3".

Add the following line to the "/etc/pam.d/system-auth" and "/etc/pam.d/password-auth" files (or modify the line to have the required value):

password required pam_pwquality.so retry=3

Check Contents

Verify AlmaLinux OS 9 is configured to limit the "pwquality" retry option to "3".

Check for the use of the "pwquality" retry option in the PAM auth files with the following command:

$ grep pam_pwquality.so /etc/pam.d/system-auth /etc/pam.d/password-auth

/etc/pam.d/system-auth:password required pam_pwquality.so retry=3
/etc/pam.d/password-auth:password required pam_pwquality.so retry=3

If the value of "retry" is set to "0" or greater than "3", or is missing from either, this is a finding.

If the system administrator (SA) can demonstrate that the required configuration is contained in a PAM configuration file included or substacked from the system-auth file, this is not a finding.

Vulnerability Number

V-269387

Documentable

False

Rule Version

ALMA-09-035990

Severity Override Guidance

Verify AlmaLinux OS 9 is configured to limit the "pwquality" retry option to "3".

Check for the use of the "pwquality" retry option in the PAM auth files with the following command:

$ grep pam_pwquality.so /etc/pam.d/system-auth /etc/pam.d/password-auth

/etc/pam.d/system-auth:password required pam_pwquality.so retry=3
/etc/pam.d/password-auth:password required pam_pwquality.so retry=3

If the value of "retry" is set to "0" or greater than "3", or is missing from either, this is a finding.

If the system administrator (SA) can demonstrate that the required configuration is contained in a PAM configuration file included or substacked from the system-auth file, this is not a finding.

Check Content Reference

M

Target Key

5664