4.5.1.3 Ensure password expiration warning days is 7 or more

Information

The warnpassword parameter in /etc/login.conf allows an administrator to notify users that their password will expire in a defined number of days. It is recommended that the warnpassword parameter be set to 7 or more days.

Providing a warning that a password will expire gives users time to think of a secure password. Users caught unaware may choose a simple password or write it down where it may be discovered.

Solution

Set the warnpassword parameter to 7d in /etc/login.conf for the default class:

:warnpassword=7d:

See Also

https://workbench.cisecurity.org/benchmarks/19044

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|4.4

Plugin: Unix

Control ID: b949bc3c14e1b7baaa2efc0216306db1c33489bb792f88406b27cc632352ea0d