Password expiration provides users with a unique time bounded password lifetime. Rationale: Allows additional security factors pertinent to a specific user to provide further password security; predetermined by varying security needs and usability requirements in a system or organization. NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To configure the global password lifetime to 365 by executing the following command: SET GLOBAL default_password_lifetime=365; Alternatively, configure the password lifetime for each user returned by the audit procedure by executing the following command: ALTER USER '<username>'@'<localhost>' PASSWORD EXPIRE INTERVAL 365 DAY; Default Value: NULL