AOSX-09-002090 - The operating system must prohibit password reuse for a minimum of five generations.

Information

Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. If the information system or application allows the user to consecutively reuse their password when that password has exceeded its defined lifetime, the end result is a password that is not changed as per policy requirements.

Solution

To set the password policy, run the following command:

sudo pwpolicy setglobalpolicy 'usingHistory=5'

See Also

http://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-9_Workstation_V1R2_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CAT|II, CCI|CCI-000200, Group-ID|V-58493, Rule-ID|SV-72923r1_rule, STIG-ID|AOSX-09-002090

Plugin: Unix

Control ID: 142b3fb81387043a28e6e6083c4a96c0add3781f9c0aeb8b7ba41be9500a8d8e