GEN000590 - The system must use a FIPS 140-2 approved cryptographic hashing algorithm for generating account password hashes.

Information

Systems must employ cryptographic hashes for passwords using the SHA-2 family of algorithms or FIPS 140-2 approved successors. The use of unapproved algorithms may result in weak password hashes more vulnerable to compromise.

Solution

Change the default password algorithm.
# authconfig --passalgo=sha512 --update

NOTE: Executing the above command will also update the required parameters in /etc/login.defs and /etc/libuser.conf

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-7, CAT|II, CCI|CCI-000803, Rule-ID|SV-218229r603259_rule, STIG-ID|GEN000590, STIG-Legacy|SV-63943, STIG-Legacy|V-22303, Vuln-ID|V-218229

Plugin: Unix

Control ID: 289c6712d8c8c4607063ee2642250ca248dbf2f59ef91f38e114df3a1f2b1e1f