Check: PHTN-67-000025
VMware vSphere 6.7 Photon OS STIG:
PHTN-67-000025
(in versions v1 r6 through v1 r1)
Title
The Photon operating system must store only encrypted representations of passwords. (Cat II impact)
Discussion
Passwords must be protected at all times via strong, one-way encryption. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised. If they are encrypted with a weak cipher, those passwords are much more vulnerable to offline brute forcing attacks.
Check Content
At the command line, execute the following command: # grep password /etc/pam.d/system-password|grep --color=always "sha512" If the output does not include "sha512", this is a finding.
Fix Text
Open /etc/applmgmt/appliance/system-password with a text editor. Add the following argument (sha512) to the password line: password required pam_unix.so sha512 shadow try_first_pass Save and close.
Additional Identifiers
Rule ID: SV-239097r877397_rule
Vulnerability ID: V-239097
Group Title: SRG-OS-000073-GPOS-00041
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000196 |
The information system, for password-based authentication, stores only cryptographically-protected passwords. |
Controls
Number | Title |
---|---|
IA-5 (1) |
Password-Based Authentication |