RHEL-06-000053 - User passwords must be changed at least every 60 days.

Information

Setting the password maximum age ensures users are required to periodically change their passwords. This could possibly decrease the utility of a stolen password. Requiring shorter password lifetimes increases the risk of users writing down the password in a convenient location subject to physical compromise.

Solution

To specify password maximum age for new accounts, edit the file '/etc/login.defs' and add or correct the following line, replacing [DAYS] appropriately:

PASS_MAX_DAYS [DAYS]

The DoD requirement is 60.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R2_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(d), CAT|II, CCI|CCI-000199, Rule-ID|SV-217889r603264_rule, STIG-ID|RHEL-06-000053, STIG-Legacy|SV-50279, STIG-Legacy|V-38479, Vuln-ID|V-217889

Plugin: Unix

Control ID: 129ea44462ce1a907627f7e34300de28816d8c41789f44a3a2b676085b401597