5.4.1.2 Ensure minimum days between password changes is 7 or more - login.defs

Information

By restricting the frequency of password changes, an administrator can prevent users from repeatedly changing their password in an attempt to circumvent password reuse controls.

Solution

Set the PASS_MIN_DAYS parameter to 7 in /etc/login.defs: PASS_MIN_DAYS 7 Modify user parameters for all users with a password set to match: # chage --mindays 7 <user>

See Also

https://workbench.cisecurity.org/files/1863

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(d), CSCv6|16

Plugin: Unix

Control ID: 7acb9923bbc202340d74da30869b5268c8e1fb94a608d1262d33da1ad407b0b1