5.3.3.4.4 Ensure pam_unix includes use_authtok

Information

use_authtok - When password changing enforce the module to set the new password to the one provided by a previously stacked password module

use_authtok allows multiple pam modules to confirm a new password before it is accepted.

Solution

Run the following script to verify the active authselect profile includes use_authtok on the password stack's pam_unix.so module lines:

#!/usr/bin/env bash

{
l_pam_profile="$(head -1 /etc/authselect/authselect.conf)"
if grep -Pq -- '^custom/' <<< "$l_pam_profile"; then
l_pam_profile_path="/etc/authselect/$l_pam_profile"
else
l_pam_profile_path="/usr/share/authselect/default/$l_pam_profile"
fi
grep -P -- '^h*passwordh+(requisite|required|sufficient)h+pam_unix.soh+([^#
r]+h+)?use_authtokb' "$l_pam_profile_path"/{password,system}-auth
}

Example output:

/etc/authselect/custom/custom-profile/password-auth:password sufficient pam_unix.so sha512 shadow {if not "without-nullok":nullok} use_authtok

/etc/authselect/custom/custom-profile/system-auth:password sufficient pam_unix.so sha512 shadow {if not "without-nullok":nullok} use_authtok

- IF - the output does not include use_authtok run the following script:

#!/usr/bin/env bash

{
l_pam_profile="$(head -1 /etc/authselect/authselect.conf)"
if grep -Pq -- '^custom/' <<< "$l_pam_profile"; then
l_pam_profile_path="/etc/authselect/$l_pam_profile"
else
l_pam_profile_path="/usr/share/authselect/default/$l_pam_profile"
fi
for l_authselect_file in "$l_pam_profile_path"/password-auth "$l_pam_profile_path"/system-auth; do
if grep -Pq '^h*passwordh+([^#
r]+)h+pam_unix.soh+([^#
r]+h+)?use_authtokb' "$l_authselect_file"; then
echo "- \"use_authtok\" is already set"
else
echo "- \"use_authtok\" is not set. Updating template"
sed -ri 's/(^s*passwords+(requisite|required|sufficient)s+pam_unix.sos+.*)$/&amp; use_authtok/g' "$l_authselect_file"
fi
done
}

Run the following command to update the password-auth and system-auth files in /etc/pam.d to include the use_authtok argument on the password stack's pam_unix.so lines:

# authselect apply-changes

See Also

https://workbench.cisecurity.org/benchmarks/18209

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5(1), 800-53|SC-28, 800-53|SC-28(1), CSCv7|16.4

Plugin: Unix

Control ID: 64b49b99bb08fa03fecc725ef3330ae06770dd73ffbeb307516e4821a833e797