5.3.3.3.3 Ensure pam_pwhistory includes use_authtok

Information

use_authtok - When password changing enforce the module to set the new password to the one provided by a previously stacked password module

use_authtok allows multiple pam modules to confirm a new password before it is accepted.

Solution

Note: The options specified on the pam_pwhistory.so module command line override the values from the pwhistory.conf configuration file. The pwhistory.conf file is the preferred method over configuring pam_pwhistory directly. Additionally, if both methods are used to set the same option, pwhistory may silently ignore one - only one method should be used.

Step 1 - Configure /etc/security/pwhistory.conf (preferred method):

Edit /etc/security/pwhistory.conf and add or set the use_authtok option:

use_authtok

Step 2 - Reconcile the pam-configs profile (conditional cleanup):

- IF - the pam_pwhistory profile in /usr/share/pam-configs/ has been used to configure pwhistory (i.e. a use_authtok argument is present on the pam_pwhistory.so line), remove that argument so the value in pwhistory.conf is the single source of truth. Run the following script:

#!/usr/bin/env bash

{
profiles=$(grep -Rl "pam_pwhistory.so" /usr/share/pam-configs/ || true)
for profile in $profiles; do
if grep -Pq '\h+pam_pwhistory\.so\h+([^#\n\r]+\h+)?use_authtok\b' "$profile"; then
sed -Ei '/pam_pwhistory\.so/s/\buse_authtok\b//g' "$profile"
sed -Ei 's/[[:space:]]+/ /g' "$profile"
echo "Updated pam profile: $profile"
pam-auth-update --package < /dev/null
fi
done
}

Verification:

After applying Step 1 (and Step 2 if applicable), confirm the setting is in effect:

# grep -Pi -- '^\h*use_authtok\b' /etc/security/pwhistory.conf
# grep -P -- '\bpam_pwhistory\.so\b' /etc/pam.d/common-password

The first command should return use_authtok . The second command should return the pam_pwhistory.so line without a use_authtok argument (so the pwhistory.conf value applies).

See Also

https://workbench.cisecurity.org/benchmarks/27797

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-28, 800-53|SC-28(1), CSCv7|16.4

Plugin: Unix

Control ID: 695e4486227fee5dc17a10a96a2a0da5a69f27f3f8aa38f1ae5ff976217551e5