5.2.5 Ensure maxexpired is configured

Information

Defines the number of weeks after maxage that a password can be reset by the user.

The maxexpired attribute limits the number of weeks after password expiry that a password may be changed by the user.

Solution

In /etc/security/user set the default user stanza maxexpired attribute to 4 :

chsec -f /etc/security/user -s default -a maxexpired=4

This means that a user can reset their password up to 4 weeks after it has expired. After this an administrative user would need to reset the password.

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2(3)

Plugin: Unix

Control ID: 9c8d9d983a863c4268cb7f5352303bf1636d5005dc2d028324e5101ceb83c01b