OSX00020 - Maximum password age

Information

The longer a password is in use, the greater the opportunity for someone to gain unauthorized knowledge of the passwords. Further, scheduled changing of passwords hinders the ability of unauthorized system users to crack passwords and gain access to a system.

Solution

Open a terminal session and use the following command to set the value for maximum password age- sudo pwpolicy -n -setglobalpolicy 'maxMinutesUntilChangePassword=86400'.

Note- For non-managed system, use the command- pwpolicy -n /Local/Default -setglobalpolicy 'maxMinutesUntilChangePassword=86400'.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx10.5_v1r2_stig_20110729.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CAT|II, Rule-ID|SV-31239r1_rule, STIG-ID|OSX00020, Vuln-ID|V-25204

Plugin: Unix

Control ID: f5567fe3101de211fdcff4249e09735f96ce3c71c4d34ea17f424fc733f821da