GEN000590 - The system must use FIPS 140-2 approved algorithm for generating password hashes

Information

System is running in Trusted Mode.

Solution

For Trusted Mode:
NOTE: There is no fix for Trusted Mode/Systems (TS). MD5 is currently used, and per vendor documentation, this algorithm will not be updated, due to TS being deprecated/replaced by SMSE.

For SMSE:
Note: There may be additional package/bundle updates that must be installed to support attributes in the /etc/default/security file.

Use the SAM/SMH interface (/etc/default/security file) to update the attribute. See the below example:
CRYPT_ALGORITHMS_DEPRECATE=__unix__
CRYPT_DEFAULT=6

If manually editing the /etc/default/security file, save any change(s) before exiting the editor.

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-000803, Rule-ID|SV-52489r3_rule, STIG-ID|GEN000590, Vuln-ID|V-22303

Plugin: Unix

Control ID: 1ccb0b65fb041926672c0e12f7c675ba8b0af81bc95aac8694063385453e83e1