5.2.1 Ensure histsize is configured

Information

Defines the number of previous passwords that a user may not reuse.

In setting the histsize attribute, it enforces a minimum number of previous passwords a user cannot reuse.

Solution

In /etc/security/user set the default user stanza histsize attribute to be 0 :

chsec -f /etc/security/user -s default -a histsize=0

This means that this setting is not being used for password management.

Impact:

The recommendation is to not use this attribute. This attribute was traditionally used together with

minage

to prevent rapid reuse of old passwords. Instead _Unique Passwords" relies solely on the time-based

histexpire

attribute.

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: Unix

Control ID: b22c5a37bc78a861a2a13f60246a28f4b9cbe7d962fd8ee526bd8893647bb5e9