3.057 - Reversible password encryption is not disabled.

Information

Storing passwords using reversible encryption is essentially the same as storing clear-text versions of the passwords. For this reason, this policy should never be enabled.

Solution

Configure the system to prevent passwords from being saved using reverse encryption.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c), CAT|II, CCI|CCI-000196, Rule-ID|SV-29688r1_rule, STIG-ID|3.057, Vuln-ID|V-2372

Plugin: Windows

Control ID: 885baea69ac4641af83e503691926ee31104fa476170be49f2312f972612ed53