5.4.1.6 Ensure all users last password change date is in the past

Information

All users should have a password change date in the past.

If a user's recorded password change date is in the future, then they could bypass any set password expiration.

Solution

Investigate any users with a password change date in the future and correct them. Locking the account, expiring the password, or resetting the password manually may be appropriate.

Examples

Reset last change date to today for a single user:

# chage -d "$(date +%Y-%m-%d)" <user>

Force password change on next login (recommended companion):

# chage -d 0 <user>

Impact:

An account with a future last-change date can permanently bypass password expiration policies - the shadow system calculates expiry relative to the last-change date, so a far-future date means the password never expires regardless of PASS_MAX_DAYS.

See Also

https://workbench.cisecurity.org/benchmarks/27798

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: Unix

Control ID: 564fe616f4e5003f309f90651944b9ff36130676e68b2a7200dca1e7d3a41f86