7.10 Ensure Password Encryption Uses SHA algorithms 'CRYPT_ALGORITHMS_ALLOW'

Information

By default Solaris uses the old unix crypt algorithm for password storage. Unix crypt is easy to crack with readily available tools. Using a more advanced algorithm decreases the capability of cracking passwords on the system.

Solution

Edit the /etc/security/policy.conf file and set the CRYPT_ALGORITHMS_ALLOW setting as follows: CRYPT_ALGORITHMS_ALLOW=5,6

See Also

https://benchmarks.cisecurity.org/tools2/solaris/CIS_Oracle_Solaris_10_Benchmark_v5.2.0.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Unix

Control ID: e5b9e11f1ed9ba7cc6669bbd4d92f8c52c1ba78fa06e1a62bbe2fb0cbcffde25