1.119 - When passwords are changed or new passwords are established, pwquality must be used.

Information

Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. "pwquality" enforces complex password construction configuration and has the ability to limit brute-force attacks on the system.

Solution

Configure the operating system to use "pwquality" to enforce password complexity rules.

Add the following line to '/etc/pam.d/system-auth' (or modify the line to have the required value):

password required pam_pwquality.so retry=3

Note: The value of "retry" should be between "1" and "3".

See Also

https://docs.fedoraproject.org/f28/system-administrators-guide/index.html

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7, CSCv6|16.7

Plugin: Unix

Control ID: 692cbfce885f51108484ffdf1b69303b7469b094a4df0669e902d823d5603923