SRG-OS-000072-ESXI5 - System must require at least 4 characters changed between old and new passwords during a password change

Information

Note: Nessus has not performed this query, and this check is only provided for informational purposes.

Solution

As root, log in to the host and ensure the expected settings of the 'min' keyword are configured in the /etc/pam.d/passwd file.
vi /etc/pam.d/passwd
Set the 'similar' keyword complexity field to 'deny', ie: similar=deny

See Also

http://iase.disa.mil/stigs/os/virtualization/Pages/index.aspx

Item Details

References: CAT|II, CCI|CCI-000195, Group-ID|V-39259, Rule-ID|SV-51075r1_rule, STIG-ID|SRG-OS-000072-ESXI5

Plugin: VMware

Control ID: cb780020014fcc5ff552652bee518459ae18fd76f93a6d9398f5a498d0583a5c