5.1.1.1 histexpire

Information

Defines the period of time in weeks that a user will not be able to reuse a password.

Rationale:

In setting the histexpire attribute, it ensures that a user cannot reuse a password within a set period of time.

Solution

In /etc/security/user, set the default user stanza histexpire attribute to be greater than or equal to 26:

chsec -f /etc/security/user -s default -a histexpire=52

This means that a user will not be able to reuse any password set in the last 52 weeks (one year).

Default Value:

Disabled

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2

Plugin: Unix

Control ID: 3e9bd81fcaac0eabd6381b97b261a7d6581a46f68d97378cea8357eb0bc1fda1