RHEL-07-010270 - The Red Hat Enterprise Linux operating system must be configured so that passwords are prohibited from reuse for a minimum of five generations.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. If the information system or application allows the user to consecutively reuse their password when that password has exceeded its defined lifetime, the end result is a password that is not changed per policy requirements.

Solution

Configure the operating system to prohibit password reuse for a minimum of five generations.

Add the following line in '/etc/pam.d/system-auth' and '/etc/pam.d/password-auth' (or modify the line to have the required value):

password requisite pam_pwhistory.so use_authtok remember=5 retry=3

Note: Manual changes to the listed files may be overwritten by the 'authconfig' program. The 'authconfig' program should not be used to update the configurations listed in this requirement.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_7_V3R7_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CAT|II, CCI|CCI-000200, Rule-ID|SV-204422r603261_rule, STIG-ID|RHEL-07-010270, STIG-Legacy|SV-86557, STIG-Legacy|V-71933, Vuln-ID|V-204422

Plugin: Unix

Control ID: 30f2461e3e045312f3468c47073fcf2c61a3732dd4bd96c291c4e08adcef35af