STIGQter STIGQter: STIG Summary: Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide Version: 1 Release: 7 Benchmark Date: 01 Jul 2026:

AlmaLinux OS 9 must be configured so that interactive user account passwords are using strong password hashes.

DISA Rule

SV-269402r1050285_rule

Vulnerability Number

V-269402

Group Title

SRG-OS-000073-GPOS-00041

Rule Version

ALMA-09-037640

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Lock all interactive user accounts not using SHA-512 hashing until the passwords can be regenerated with SHA-512.

Check Contents

Verify that the interactive user account passwords are using a strong password hash with the following command:

$ cut -d: -f1,2 /etc/shadow

root:$6$88upzIIyml/6UEya$QMLbF.L6gMNnIhzcxRorHgubK6jl3CHZ.MZrMkrEApOlt/MP.N.BFea.ykhPnIS.EYICo6To42koq0DCH8AjB/
bin:*
daemon:*

Password hashes "!" or "*" indicate inactive accounts not available for logon and are not evaluated.

If any interactive user password hash does not begin with "$6", this is a finding.

Vulnerability Number

V-269402

Documentable

False

Rule Version

ALMA-09-037640

Severity Override Guidance

Verify that the interactive user account passwords are using a strong password hash with the following command:

$ cut -d: -f1,2 /etc/shadow

root:$6$88upzIIyml/6UEya$QMLbF.L6gMNnIhzcxRorHgubK6jl3CHZ.MZrMkrEApOlt/MP.N.BFea.ykhPnIS.EYICo6To42koq0DCH8AjB/
bin:*
daemon:*

Password hashes "!" or "*" indicate inactive accounts not available for logon and are not evaluated.

If any interactive user password hash does not begin with "$6", this is a finding.

Check Content Reference

M

Target Key

5664