OSX00040 - Check newly-created password content for account or user name.

Information

Configure the local system to verify that newly-created passwords do not contain user's account name or parts of the user's full name that exceed two consecutive characters.

Solution

Open a terminal session and use the following command to set the value for Password cannot be name- sudo pwpolicy -n -setglobalpolicy 'passwordCannotBeName=1'.

Note- For non-managed system, use the command- pwpolicy -n /Local/Default -setglobalpolicy 'passwordCannotBeName=1'.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx10.5_v1r2_stig_20110729.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CAT|II, Rule-ID|SV-31281r1_rule, STIG-ID|OSX00040, Vuln-ID|V-25238

Plugin: Unix

Control ID: b9a9616ffb2b2c8df9c0defb610d71b12a0acf1f476333f1e068e69c7ddbf0fc