STIGQter STIGQter: STIG Summary: Nutanix Acropolis GPOS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

Operating systems must enforce 24 hours/1 day as the minimum password lifetime.

DISA Rule

SV-279609r1192569_rule

Vulnerability Number

V-279609

Group Title

SRG-OS-000075-GPOS-00043

Rule Version

NXAC-OS-000166

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Nutanix OS to use complex password.

1. For AOS, enter the following command.

$ sudo salt-call state.sls security/CVM/pamCVM.sls

2. For Prism Central, enter the following command.

$ sudo salt-call state.sls security/PCVM/pamPCVM.sls

3. For Files, enter the following command.

$ sudo salt-call state.sls security/AFS/pamAFS.sls

4. For AHV OS CVM, enter the following command.

$ ncli cluster edit-hypervisor-security-params enable-high-strength-password=true

Check Contents

1. Verify Nutanix AOS is configured to enforce 24hour/1day minimum password lifetime using the following command.

$ sudo grep -i pass_min_days /etc/login.defs
PASS_MIN_DAYS 1

If the "PASS_MIN_DAYS" parameter value is not "1" or greater, or is commented out, this is a finding.

2. Run the following command.

$ sudo awk -F: '$4 < 1 {print $1 " " $4}' /etc/shadow

If any results are returned that are not associated with a system account, this is a finding.

Vulnerability Number

V-279609

Documentable

False

Rule Version

NXAC-OS-000166

Severity Override Guidance

1. Verify Nutanix AOS is configured to enforce 24hour/1day minimum password lifetime using the following command.

$ sudo grep -i pass_min_days /etc/login.defs
PASS_MIN_DAYS 1

If the "PASS_MIN_DAYS" parameter value is not "1" or greater, or is commented out, this is a finding.

2. Run the following command.

$ sudo awk -F: '$4 < 1 {print $1 " " $4}' /etc/shadow

If any results are returned that are not associated with a system account, this is a finding.

Check Content Reference

M

Target Key

5730