STIGQter STIGQter: STIG Summary: Canonical Ubuntu 16.04 Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 24 Jan 2020: The passwd command must be configured to prevent the use of dictionary words as passwords.

DISA Rule

SV-90163r1_rule

Vulnerability Number

V-75483

Group Title

SRG-OS-000480-GPOS-00225

Rule Version

UBTU-16-010270

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Ubuntu operating system to prevent the use of dictionary words for passwords.

Edit the file "/etc/pam.d/passwd" and add the following line:

@ include common-password

Check Contents

Verify the "passwd" command uses the common-password settings.

Check that the "passwd" command uses the common-password option with the following command:

# grep common-password /etc/pam.d/passwd

@ include common-password

If the command does not return a line, or the line is commented out, this is a finding.

Vulnerability Number

V-75483

Documentable

False

Rule Version

UBTU-16-010270

Severity Override Guidance

Verify the "passwd" command uses the common-password settings.

Check that the "passwd" command uses the common-password option with the following command:

# grep common-password /etc/pam.d/passwd

@ include common-password

If the command does not return a line, or the line is commented out, this is a finding.

Check Content Reference

M

Target Key

3075

Comments