5.2.12 Ensure minother is configured

Information

Defines the number of characters within a password which must be non-alphabetic.

In setting the minother attribute, it increases password complexity by enforcing the use of non-alphabetic characters in every user password.

Solution

In /etc/security/user set the default user stanza minother attribute to be greater than or equal to 3 :

chsec -f /etc/security/user -s default -a minother=3

This means that there must be at least 3 non-alphabetic characters within a password.

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: Unix

Control ID: 5678624c97c760b429e0345b63ac7021a3badb907e2b7e829c1830399aebaf45