5.2.15 Ensure minloweralpha is configured

Information

Defines the minimum number of lower case alphabetic characters in a password.

In setting the minloweralpha attribute, the password must contain a lower case alphabetic character when it is changed by the user.

Solution

In /etc/security/user set the default user stanza minloweralpha attribute to 1 :

chsec -f /etc/security/user -s default -a minloweralpha=1

This means that there must be at least 1 lower case alphabetic character within a password.

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: Unix

Control ID: f94f3fee4079f0b65619e00ffe19ee23a90065b0971defa8e8514c25d28e4527