5.2.4 minlen

Information

Defines the minimum length of a password.

Rationale:

In setting the minlen attribute, it ensures that passwords meet the required length criteria.

Solution

In /etc/security/user, set the default user stanza minlen attribute to be greater than or equal to 14:

chsec -f /etc/security/user -s default -a minlen=14

This means that all user passwords must be at least 14 characters in length.
NOTE: To support a password length greater than 8 characters the default algorithm must be changed. If the command above returns an error (3004-692 Error changing 'minlen' to '14' : Value is invalid.) the recommendation 3.1.15 /etc/security/login.cfg - pwd_algorithm needs to be completed first.

Default Value:

default minlen=0

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: Unix

Control ID: e29d3a3d1f7402b6026439c25330ce72d0d85e27000c0e5f050470d3c2681f54