Information
The PASS_MIN_DAYS parameter in /etc/login.defs allows an administrator to prevent users from changing their password until a minimum number of days have passed since the last time the user changed their password. It is recommended that PASS_MIN_DAYS parameter be set to 7 or more days.
Rationale:
By restricting the frequency of password changes, an administrator can prevent users from repeatedly changing their password in an attempt to circumvent password reuse controls.
Solution
Set the PASS_MIN_DAYS parameter to 7 in /etc/login.defs :
PASS_MIN_DAYS 7
Modify user parameters for all users with a password set to match:
# chage --mindays 7 <user>
Notes:
You can also check this setting in /etc/shadow directly. The 4th field should be 7 or more for all users with a password.
This Benchmark recommendation maps to:
Red Hat Enterprise Linux 7 Security Technical Implementation Guide:
Version 2, Release: 3 Benchmark Date: 26 Apr 2019
Vul ID: V-71925
Rule ID: SV-86549r2_rule
STIG ID: RHEL-07-010230
Severity: CAT II
Vul ID: V-71927
Rule ID: SV-86551r2_rule
STIG ID: RHEL-07-010240
Severity: CAT II