SRG-OS-000072-ESXI5 - System must require at least 4 characters changed between old and new passwords during a password change

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Note: Nessus has not performed this query, and this check is only provided for informational purposes.

Solution

As root, log in to the host and ensure the expected settings of the 'min' keyword are configured in the /etc/pam.d/passwd file.
vi /etc/pam.d/passwd
Set the 'similar' keyword complexity field to 'deny', ie: similar=deny

See Also

http://iase.disa.mil/stigs/os/virtualization/Pages/index.aspx

Item Details

References: CAT|II, CCI|CCI-000195, Group-ID|V-39259, Rule-ID|SV-51075r1_rule, STIG-ID|SRG-OS-000072-ESXI5

Plugin: VMware

Control ID: cb780020014fcc5ff552652bee518459ae18fd76f93a6d9398f5a498d0583a5c