STIGQter STIGQter: STIG Summary: VMware vRealize Operations Manager 6.x SLES Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

The SLES for vRealize must prevent the use of dictionary words for passwords.

DISA Rule

SV-99413r1_rule

Vulnerability Number

V-88763

Group Title

SRG-OS-000480-GPOS-00225

Rule Version

VROM-SL-001485

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure SLES for vRealize to prevent the use of dictionary words for passwords. Procedure:

Edit the file "/etc/pam.d/passwd". Configure "passwd" by adding a line such as:

password include common-password

Save the changes made to the file.

Check Contents

Verify the "passwd" command uses the "common-password" settings.

Procedure:

# grep common-password /etc/pam.d/passwd

If line "password include common-password" is not found then the password checks in common-password will not be applied to new passwords, and this is a finding.

Vulnerability Number

V-88763

Documentable

False

Rule Version

VROM-SL-001485

Severity Override Guidance

Verify the "passwd" command uses the "common-password" settings.

Procedure:

# grep common-password /etc/pam.d/passwd

If line "password include common-password" is not found then the password checks in common-password will not be applied to new passwords, and this is a finding.

Check Content Reference

M

Target Key

3461

Comments