AZLX-23-002489 - Amazon Linux 2023 must ensure the password complexity module is enabled in the password-auth file.

Information

Enabling PAM password complexity permits enforcement of strong passwords and consequently makes the system less prone to dictionary attacks.

Solution

Configure Amazon Linux 2023 to use "pwquality" to enforce password complexity rules.

Add the following line to the "/etc/pam.d/password-auth" file (or modify the line to have the required value):

password required pam_pwquality.so

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Amazon_Linux_2023_V1R1_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(a), CAT|II, CCI|CCI-000192, CCI|CCI-000193, CCI|CCI-004066, Rule-ID|SV-274161r1120471_rule, STIG-ID|AZLX-23-002489, Vuln-ID|V-274161

Plugin: Unix

Control ID: 3cf5c7851778d821c12d86aae996c7c9af98ae9acbe13d7517efc17f7d9c5971