Revision 1.4

Apr 12, 2023
Functional Update
  • UBTU-18-010100 - The Ubuntu operating system must enforce password complexity by requiring that at least one upper-case character be used - ucredit
  • UBTU-18-010101 - The Ubuntu operating system must enforce password complexity by requiring that at least one lower-case character be used - lcredit
  • UBTU-18-010102 - The Ubuntu operating system must enforce password complexity by requiring that at least one numeric character be used - dcredit
  • UBTU-18-010103 - The Ubuntu operating system must require the change of at least 8 characters when passwords are changed - difok
  • UBTU-18-010106 - The Ubuntu operating system must enforce 24 hours/1 day as the minimum password lifetime. Passwords for new users must have a 24 hours/1 day minimum password lifetime restriction.
  • UBTU-18-010107 - The Ubuntu operating system must enforce a 60-day maximum password lifetime restriction. Passwords for new users must have a 60-day maximum password lifetime restriction.
  • UBTU-18-010109 - The Ubuntu operating system must enforce a minimum 15-character password length.
  • UBTU-18-010110 - The Ubuntu operating system must employ a FIPS 140-2 approved cryptographic hashing algorithms for all created and stored passwords - ENCRYPT_METHOD
  • UBTU-18-010113 - The Ubuntu operating system must prevent the use of dictionary words for passwords.
  • UBTU-18-010116 - The Ubuntu Operating system must be configured so that when passwords are changed or new passwords are established, pwquality must be used - pwquality.conf enforcing
  • UBTU-18-010145 - The Ubuntu operating system must enforce password complexity by requiring that at least one special character be used.
  • UBTU-18-010448 - The Ubuntu operating system default filesystem permissions must be defined in such a way that all authenticated users can only read and modify their own files.
Miscellaneous
  • Metadata updated.
  • Platform check updated.
  • Variables updated.
Removed
  • UBTU-18-010104 - The Ubuntu operating system must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm.