5.3.1.3 Ensure latest version of libpwquality is installed

Information

libpwquality provides common functions for password quality checking and scoring them based on their apparent randomness. The library also provides a function for generating random passwords with good pronounceability.

This module can be plugged into the password stack of a given service to provide some plug-in strength-checking for passwords. The code was originally based on pam_cracklib module and the module is backwards compatible with its options.

Strong passwords reduce the risk of systems being hacked through brute force methods.

Solution

Run the following command to install libpwquality :

# dnf install libpwquality

- IF - the version of libpwquality on the system is less that version libpwquality-1.4.4-8 :

Run the following command to update to the latest version of libpwquality :

# dnf upgrade libpwquality

See Also

https://workbench.cisecurity.org/benchmarks/18209

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2c.

Plugin: Unix

Control ID: c225949bd7d2a27fcd6191bbe4ec5ad93f8d4a008c95c976c0569f647bda830b