4.4.2.4.4 Ensure pam_unix includes use_authtok

Information

use_authtok - When password changing enforce the module to set the new password to the one provided by a previously stacked password module

use_authtok allows multiple pam modules to confirm a new password before it is accepted.

Solution

Edit the files /etc/pam.d/system-auth and /etc/pam.d/password-auth:

Edit the following line and add the use_authtok argument:

password sufficient pam_unix.so sha512 shadow try_first_pass use_authtok

See Also

https://workbench.cisecurity.org/benchmarks/15962

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5(1), 800-53|SC-28, 800-53|SC-28(1), CSCv7|16.4

Plugin: Unix

Control ID: 4b9fe2abb65fc3e5cbf0411fad772effb8e6268f58d9087456971fc25fe5ad9b