GEN000790-ESXI5-000085 - The system must prevent the use of dictionary words for passwords (V-39246)

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version


An easily guessable password provides an open door to any external or internal malicious intruder. Many computer compromises occur as the result of account name and password guessing. This is generally done by someone with an automated script using repeated logon attempts until the correct account and password pair is guessed. Utilities, such as cracklib, can be used to validate passwords are not dictionary words and meet other criteria during password changes.


As root, log in to the host and ensure the expected settings of the 'min' keyword are configured in the /etc/pam.d/passwd file.
vi /etc/pam.d/passwd
Set the 'N2' password complexity field to 'disabled', ie: min=disabled,disabled,disabled,disabled,14

References: CAT|II, CCI|CCI-000366, Group-ID|V-39246, Rule-ID|SV-51276r1_rule, STIG-ID|GEN000790-ESXI5-000085, Vuln-ID|V-39418

Plugin: VMware

Control ID: 933f0dca381bea578f2e277722c779fc08d0b31b2602cfbf9edb4fc84fd59b45