GEN000790-ESXI5-000085 - The system must prevent the use of dictionary words for passwords (V-39418)

Information

An easily guessable password provides an open door to any external or internal malicious intruder. Many computer compromises occur as the result of account name and password guessing. This is generally done by someone with an automated script using repeated logon attempts until the correct account and password pair is guessed. Utilities, such as cracklib, can be used to validate passwords are not dictionary words and meet other criteria during password changes.

Solution

As root, log in to the host and ensure the expected settings of the 'min' keyword are configured in the /etc/pam.d/passwd file.
vi /etc/pam.d/passwd
Set the 'N2' password complexity field to 'disabled', ie: min=disabled,disabled,disabled,disabled,14

See Also

http://iase.disa.mil/stigs/os/virtualization/Pages/index.aspx

Item Details

References: CAT|II, CCI|CCI-000366, Group-ID|V-39418, Rule-ID|SV-51276r1_rule, STIG-ID|GEN000790-ESXI5-000085

Plugin: VMware

Control ID: 933f0dca381bea578f2e277722c779fc08d0b31b2602cfbf9edb4fc84fd59b45