5.1.1.3 minage

Information

Defines the minimum number of weeks before a password can be changed.

Rationale:

The minage attribute prohibits users changing their password until a set number of weeks have passed.

Impact:

The AIX community prefers to rely on the AIX attribute histexpire rather than a historical minage value.

Historically, the minage attribute has been used to prevent a user from write a script to spool through histsize passwords, and then return to the same password as before. The attribute histexpire overrides histsize. Therefore, there is no need to force a user to request assistance from system administrators in order to reset a poorly chosen password, or in the case of special accounts that policy states passwords are meant for 'one time use'.

Again, since AIX has a different way to prevent scripted password re-cycling, the need for minage is not longer warranted.

Solution

In/etc/security/user, set the default user stanza minage attribute to 1:

chsec -f /etc/security/user -s default -a minage=1

This means that a user can only change their password after one week.

Default Value:

minage=0

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2

Plugin: Unix

Control ID: fa43a4288fb810c1ed479c9886c32f1715344bfa86efda2768212b08ca8ab86c