7.10 Ensure Password Encryption Uses SHA algorithms 'CRYPT_DEFAULT'

Information

By default Solaris uses the old unix crypt algorithm for password storage. Unix crypt is easy to crack with readily available tools. Using a more advanced algorithm decreases the capability of cracking passwords on the system.

Solution

Edit the /etc/security/policy.conf file and set the CRYPT_DEFAULT setting as follows: CRYPT_DEFAULT=6

See Also

https://benchmarks.cisecurity.org/tools2/solaris/CIS_Oracle_Solaris_10_Benchmark_v5.2.0.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Unix

Control ID: 239911db76622577e62acf3e65e73cdd078397d8ccfb3d5a92e7684c0c2d10d0