Check: RHEL-09-611045
RHEL 9 STIG:
RHEL-09-611045
(in version v2 r3)
Title
RHEL 9 must ensure the password complexity module is enabled in the system-auth file. (Cat II impact)
Discussion
Enabling PAM password complexity permits enforcement of strong passwords and consequently makes the system less prone to dictionary attacks.
Check Content
Verify RHEL 9 uses "pwquality" to enforce the password complexity rules in the system-auth file with the following command: $ grep pam_pwquality /etc/pam.d/system-auth password required pam_pwquality.so If the command does not return a line containing the value "pam_pwquality.so", or the line is commented out, this is a finding. If the system administrator (SA) can demonstrate that the required configuration is contained in a PAM configuration file included or substacked from the system-auth file, this is not a finding.
Fix Text
Configure RHEL 9 to use "pwquality" to enforce password complexity rules. Add the following line to the "/etc/pam.d/system-auth" file(or modify the line to have the required value): password required pam_pwquality.so
Additional Identifiers
Rule ID: SV-258098r1045195_rule
Vulnerability ID: V-258098
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |