6.3.5 Limit Password Reuse - password sufficient pam_unix.o <existing options> remember=5

Information

The /etc/security/opasswd file stores the users' old passwords and can be checked to ensure that users are not recycling recent passwords.

Rationale:

Forcing users not to reuse their past 5 passwords make it less likely that an attacker will be able to guess the password.

Solution

Set the pam_unix.so remember parameter to 5 or more in /etc/pam.d/system_auth:

password sufficient pam_unix.so remember=5

Default Value:

OS Default: N/A

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: Unix

Control ID: d8d77a26c6922103de8c317d8eb6039a6f063f71bd0c285d0bbeef0b577c825b