GEN000680 - The system must require passwords to contain no more than three consecutive repeating characters.

Information

To enforce the use of complex passwords, the number of consecutive repeating characters is limited. Passwords with excessive repeated characters may be more vulnerable to password-guessing attacks.

Solution

Edit /etc/default/passwd and set MAXREPEATS to 3.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-227590r603266_rule, STIG-ID|GEN000680, STIG-Legacy|SV-27126, STIG-Legacy|V-11975, Vuln-ID|V-227590

Plugin: Unix

Control ID: c9487b74b00664b977331292da8333907efe9349233c7c29148fa3a3699d30a4