5.1.1.2 histsize

Information

Defines the number of previous passwords that a user may not reuse.

Rationale:

In setting the histsize attribute, it enforces a minimum number of previous passwords a user cannot reuse.

Impact:

The recommendation is to not use this attribute. This attribute was traditionally used together with minage to prevent rapid reuse of old passwords. Instead _Unique Passwords' relies solely on the time-based histexpire attribute.

Solution

In /etc/security/user, set the default user stanza histsize attribute to be 0:

chsec -f /etc/security/user -s default -a histsize=0

This means that this setting is not being used for password management.

Default Value:

Disabled

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2

Plugin: Unix

Control ID: 35b5a2c601df251dde69bcc78d737c5eaeb20cd9bce2e497b31f7500aba98a6c