GEN000000-HPUX0450 - System must determine if password aging is inherited from /etc/default/security when not specified in shadow file

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Password aging attributes are stored in /etc/default/security and /etc/shadow. Anytime a password aging policy is changed, policy requirements are updated in /etc/default/security. If the system is allowed to override or ignore updates made to /etc/default/security, deprecated password aging policies will remain intact and never enforce newer requirements.

Solution

If the system is operating in Trusted Mode, no fix is required.

For SMSE:
Note: There may be additional package/bundle updates that must be installed to support attributes in the /etc/default/security file.

Use the SAM/SMH interface (/etc/default/security file) to update the OVERRIDE_SYSDEF_PWAGE attribute. See the below example:
OVERRIDE_SYSDEF_PWAGE=0

Note: If manually editing the /etc/default/security file, save any change(s) before exiting the editor.

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CAT|II, CCI|CCI-000366, Rule-ID|SV-52481r1_rule, STIG-ID|GEN000000-HPUX0450, Vuln-ID|V-40492

Plugin: Unix

Control ID: 089a4acf0467b407d794e91730b71dd48af9b0a03573fa52c3c6e96cf4bcfb8e