8.2 Verify That There Are No Accounts With Empty Password Fields

Information

An account with an empty password field means that anybody may log in as that user without providing a password at all. All accounts should have strong passwords or should be locked by using a password string like 'NP' or '*LOCKED*'.

See Also

https://workbench.cisecurity.org/files/633

Item Details

Audit Name: CIS Solaris 9 v1.3

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(a)

Plugin: Unix

Control ID: e473bbd4fdb772a021685b26104cb7eb96625246c8d7ba41eb6fa238c5594d10