Information
libpwquality provides common functions for password quality checking and scoring them based on their apparent randomness. The library also provides a function for generating random passwords with good pronounceability.
This module can be plugged into the password stack of a given service to provide some plug-in strength-checking for passwords. The code was originally based on pam_cracklib module and the module is backwards compatible with its options.
Strong passwords reduce the risk of systems being hacked through brute force methods.
Older versions of the libpam-pwquality package may not include the latest security and feature patches and updates.
Recommendations were written and tested against version 1.3.1-5ubuntu4.7 The latest available version should be used.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
Run the following command to install the latest version of libpam-pwquality :
# apt install libpam-pwquality