5.3.1.3 Ensure latest version of libpam-pwquality is installed

Information

libpwquality provides common functions for password quality checking and scoring them based on their apparent randomness. The library also provides a function for generating random passwords with good pronounceability.

This module can be plugged into the password stack of a given service to provide some plug-in strength-checking for passwords. The code was originally based on pam_cracklib module and the module is backwards compatible with its options.

Strong passwords reduce the risk of systems being hacked through brute force methods.

Older versions of the libpam-pwquality package may not include the latest security and feature patches and updates.

Recommendations were written and tested against version 1.3.1-5ubuntu4.7 The latest available version should be used.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Run the following command to install the latest version of libpam-pwquality :

# apt install libpam-pwquality

See Also

https://workbench.cisecurity.org/benchmarks/21369

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: Unix

Control ID: 17d90038dc48e287ccc56cb7c3a7ff84a118f6a771201e21825817606c413a7c