Check: RHEL-09-611045
RHEL 9 STIG:
RHEL-09-611045
(in versions v1 r3 through v1 r1)
Title
RHEL 9 must ensure the password complexity module is enabled in the system-auth file. (Cat II impact)
Discussion
Enabling PAM password complexity permits enforcement of strong passwords and consequently makes the system less prone to dictionary attacks.
Check Content
Verify RHEL 9 uses "pwquality" to enforce the password complexity rules in the system-auth file with the following command: $ cat /etc/pam.d/system-auth | grep pam_pwquality password required pam_pwquality.so If the command does not return a line containing the value "pam_pwquality.so", or the line is commented out, this is a finding.
Fix Text
Configure RHEL 9 to use "pwquality" to enforce password complexity rules. Add the following line to the "/etc/pam.d/system-auth" file(or modify the line to have the required value): password required pam_pwquality.so
Additional Identifiers
Rule ID: SV-258098r926281_rule
Vulnerability ID: V-258098
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |