5.3.3.3.3 Ensure pam_pwhistory includes use_authtok

Information

use_authtok - When password changing enforce the module to set the new password to the one provided by a previously stacked password module

use_authtok allows multiple pam modules to confirm a new password before it is accepted.

Solution

Edit or add the following line in /etc/security/pwhistory.conf :

use_authtok

- OR/IF - The pam_pwhistory profile in /usr/share/pam-configs/ has been used to configure pwhistory . Run the following script to remove the use_authtok argument to the pam_pwhistory line in the Password section:

#!/usr/bin/env bash

{
profiles=$(grep -Rl "pam_pwhistory.so" /usr/share/pam-configs/ || true)
for profile in $profiles; do
if grep -Pq '\h+pam_pwhistory\.so\h+([^#\n\r]+\h+)?use_authtok\b' "$profile"; then
sed -Ei '/pam_pwhistory\.so/s/\use_authtok\b//g' "$profile"
sed -Ei 's/[[:space:]]+/ /g' "$profile"
echo "Updated pam profile: $profile"
pam-auth-update --package < /dev/null
fi
done
}

Note : The options specified on the pwhistory.so module command line override the values from the pwhistory.conf configuration file. The pwhistory.conf file is the preferred method over configuring pam_pwhistory directly.

See Also

https://workbench.cisecurity.org/benchmarks/24932

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-28, 800-53|SC-28(1), CSCv7|16.4

Plugin: Unix

Control ID: 695e4486227fee5dc17a10a96a2a0da5a69f27f3f8aa38f1ae5ff976217551e5