SV-282459r1200357_rule
V-282459
SRG-OS-000073-GPOS-00041
TOSS-05-000356
CAT II
10
Configure TOSS 5 to encrypt all stored passwords with a strong cryptographic hash.
Edit/modify the following line in the "/etc/login.defs" file and set "SHA_CRYPT_MIN_ROUNDS" to a value no lower than "5000":
SHA_CRYPT_MIN_ROUNDS 5000
Verify TOSS 5 has a minimum number of hash rounds configured using the following command:
$ grep -i sha_crypt /etc/login.defs
If "SHA_CRYPT_MIN_ROUNDS" or "SHA_CRYPT_MAX_ROUNDS" is less than "5000", this is a finding.
V-282459
False
TOSS-05-000356
Verify TOSS 5 has a minimum number of hash rounds configured using the following command:
$ grep -i sha_crypt /etc/login.defs
If "SHA_CRYPT_MIN_ROUNDS" or "SHA_CRYPT_MAX_ROUNDS" is less than "5000", this is a finding.
M
5738