5.3.2.4.1 Ensure pam_unix does not include nullok

Information

The nullok argument overrides the default action of pam_unix.so to not permit the user access to a service if their official password is blank.

Using a strong password is essential to helping protect personal and sensitive information from unauthorized access

Solution

Run the following command to delete the nullok argument from the pam_unix.so module:

# pam-config -d --unix --unix-nullok

See Also

https://workbench.cisecurity.org/benchmarks/20333

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: Unix

Control ID: ea661060d7e0401f950e8daebe038b8aa5316431bf94446756370b4df585b763