5.2.11 Ensure minalpha is configured

Information

Defines the minimum number of alphabetic characters in a password.

In setting the minalpha attribute, it ensures that passwords have a minimum number of alphabetic characters.

Solution

In /etc/security/user set the default user stanza minalpha attribute to be greater than or equal to 3 :

chsec -f /etc/security/user -s default -a minalpha=3

This means that there must be at least 3 alphabetic characters (upper or lowercase) within a password.

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: Unix

Control ID: ab99f80781087882ccb11910bd8601696ad6f355912e2e83d6ae913d25308828