OSX00025 - Minimum password age

Information

Permitting passwords to be changed in immediate succession within the same day, allows users to cycle passwords through their history database. This enables users to effectively negate the purpose of mandating periodic password changes.

Solution

Open a terminal session and use the following command to set the value for minimum password age- sudo pwpolicy -n -setglobalpolicy 'minMinutesUntilChangePassword=1440'.

Note- For non-managed system, use the command- pwpolicy -n /Local/Default -setglobalpolicy 'minMinutesUntilChangePassword=1440'.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx10.5_v1r2_stig_20110729.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CAT|II, Rule-ID|SV-31267r1_rule, STIG-ID|OSX00025, Vuln-ID|V-25226

Plugin: Unix

Control ID: 96402102b475a3b83b4c033e7940740be926d8369fb9d63fa13c86177d0f0ade