SOL-11.1-040130 - Systems must employ cryptographic hashes for passwords using the SHA-2 family of algorithms or FIPS 140-2 approved successors.

Information

Cryptographic hashes provide quick password authentication while not actually storing the password.

Solution

The root role is required.

Configure the system to disallow the use of UNIX encryption and enable SHA256 as the default encryption hash.

# pfedit /etc/security/policy.conf

Check that the lines:
CRYPT_DEFAULT=6
CRYPT_ALGORITHMS_ALLOW=5,6

exist and are not commented out.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_x86_V2R9_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c), CAT|II, CCI|CCI-000196, Rule-ID|SV-216098r603268_rule, STIG-ID|SOL-11.1-040130, STIG-Legacy|SV-61115, STIG-Legacy|V-48243, Vuln-ID|V-216098

Plugin: Unix

Control ID: 7994a506354b12cfd2c7c15118458ddf33e148b7a1ee11bcae6b8aa63076a53c