SRG-OS-000072-ESXI5 - System must require at least 4 characters changed between old and new passwords during a password change

Information

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

As root, log in to the host and ensure the expected settings of the 'min' keyword are configured in the /etc/pam.d/passwd file.
vi /etc/pam.d/passwd
Set the 'similar' keyword complexity field to 'deny', ie: similar=deny

See Also

http://iasecontent.disa.mil/stigs/zip/U_ESXi5_Server_V1R10_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000195, Group-ID|V-39259, Rule-ID|SV-51075r1_rule, STIG-ID|SRG-OS-000072-ESXI5, Vuln-ID|V-39259

Plugin: VMware

Control ID: cb780020014fcc5ff552652bee518459ae18fd76f93a6d9398f5a498d0583a5c