CCI|CCI-000196

Title

The information system, for password-based authentication, stores only cryptographically-protected passwords.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
GEN002000 - There must be no .netrc files on the systemUnixDISA STIG HP-UX 11.31 v1r19
3.057 - Reversible password encryption is not disabled.WindowsDISA Windows Server 2008 MS STIG v6r46
3.057 - Reversible password encryption is not disabled.WindowsDISA Windows Server 2008 DC STIG v6r47
3.057 - Reversible password encryption is not disabled.WindowsDISA Windows Vista STIG v6r41
3.057 - Reversible password encryption must be disabled.WindowsDISA Windows 7 STIG v1r32
3.057 - Reversible password encryption will be disabled.WindowsDISA Windows Server 2008 R2 DC STIG v1r34
3.057 - Reversible password encryption will be disabled.WindowsDISA Windows Server 2008 R2 MS STIG v1r33
3.073 - The system is configured to store the LAN Manager hash of the password in the SAM.WindowsDISA Windows 7 STIG v1r32
3.073 - The system is configured to store the LAN Manager hash of the password in the SAM.WindowsDISA Windows Server 2008 MS STIG v6r46
3.073 - The system is configured to store the LAN Manager hash of the password in the SAM.WindowsDISA Windows Server 2008 DC STIG v6r47
3.073 - The system must be configured to prevent the storage of the LAN Manager hash of passwords.WindowsDISA Windows Vista STIG v6r41
3.073 - The system will be configured to prevent the storage of the LAN Manager hash of passwords.WindowsDISA Windows Server 2008 R2 DC STIG v1r34
3.073 - The system will be configured to prevent the storage of the LAN Manager hash of passwords.WindowsDISA Windows Server 2008 R2 MS STIG v1r33
5.4.3 Ensure password hashing algorithm is SHA-512UnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
5.5.1.6 Ensure shadow file is configured to use only encrypted representations of passwordsUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
5.5.6 Ensure user and group account administration utilities are configured to store only encrypted representations of passwordsUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords - bindpwd DESUnixDISA STIG AIX 7.x v2r1
AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords - bindpwd DESUnixDISA STIG AIX 7.x v2r5
AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords - bindpwd DESUnixDISA STIG AIX 7.x v2r9
AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords - bindpwd DESUnixDISA STIG AIX 7.x v2r3
AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords - bindpwd DESUnixDISA STIG AIX 7.x v2r6
AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords - bindpwd DESUnixDISA STIG AIX 7.x v2r8
AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords - ldapsslkeypwdUnixDISA STIG AIX 7.x v2r6
AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords - ldapsslkeypwdUnixDISA STIG AIX 7.x v2r8
AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords - ldapsslkeypwdUnixDISA STIG AIX 7.x v2r1
AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords - ldapsslkeypwdUnixDISA STIG AIX 7.x v2r3
AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords - ldapsslkeypwdUnixDISA STIG AIX 7.x v2r5
AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords - ldapsslkeypwdUnixDISA STIG AIX 7.x v2r9
AIX7-00-003101 - The AIX system must have no .netrc files on the system.UnixDISA STIG AIX 7.x v2r3
AIX7-00-003101 - The AIX system must have no .netrc files on the system.UnixDISA STIG AIX 7.x v2r6
AIX7-00-003101 - The AIX system must have no .netrc files on the system.UnixDISA STIG AIX 7.x v2r8
AIX7-00-003101 - The AIX system must have no .netrc files on the system.UnixDISA STIG AIX 7.x v2r1
AIX7-00-003101 - The AIX system must have no .netrc files on the system.UnixDISA STIG AIX 7.x v2r5
AIX7-00-003101 - The AIX system must have no .netrc files on the system.UnixDISA STIG AIX 7.x v2r9
Big Sur - Encrypt Stored PasswordsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Encrypt Stored PasswordsUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Encrypt Stored PasswordsUnixNIST macOS Big Sur v1.4.0 - 800-171
Big Sur - Encrypt Stored PasswordsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Encrypt Stored PasswordsUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Encrypt Stored PasswordsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Encrypt Stored PasswordsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Low
Big Sur - Encrypt Stored PasswordsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Encrypt Stored PasswordsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Low
CISC-ND-000620 - The Cisco router must only store cryptographic representations of passwords.CiscoDISA STIG Cisco IOS Router NDM v2r3
CISC-ND-000620 - The Cisco router must only store cryptographic representations of passwords.CiscoDISA STIG Cisco IOS Router NDM v2r8
CISC-ND-000620 - The Cisco router must only store cryptographic representations of passwords.CiscoDISA STIG Cisco IOS XE Router NDM v2r9
CISC-ND-000620 - The Cisco router must only store cryptographic representations of passwords.CiscoDISA STIG Cisco IOS Router NDM v2r2
CISC-ND-000620 - The Cisco router must only store cryptographic representations of passwords.CiscoDISA STIG Cisco IOS Router NDM v2r7
CISC-ND-000620 - The Cisco router must only store cryptographic representations of passwords.CiscoDISA STIG Cisco IOS XE Router NDM v2r3
CISC-ND-000620 - The Cisco router must only store cryptographic representations of passwords.CiscoDISA STIG Cisco IOS XE Router NDM v2r7