OL6-00-000053 - User passwords must be changed at least every 60 days.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Setting the password maximum age ensures users are required to periodically change their passwords. This could possibly decrease the utility of a stolen password. Requiring shorter password lifetimes increases the risk of users writing down the password in a convenient location subject to physical compromise.

Solution

To specify password maximum age for new accounts, edit the file '/etc/login.defs' and add or correct the following line, replacing [DAYS] appropriately:

PASS_MAX_DAYS [DAYS]

The DoD requirement is 60.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_6_V2R6_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000199, Rule-ID|SV-208828r793613_rule, STIG-ID|OL6-00-000053, STIG-Legacy|SV-65001, STIG-Legacy|V-50795, Vuln-ID|V-208828

Plugin: Unix

Control ID: bc8f8854d2110d1456e59799153cbe9fe988bbc4d553fc1bba67938b4ec92c25