Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35314 | SRG-APP-000168-AS-000116 | SV-46601r1_rule | Medium |
Description |
---|
Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. Use of a complex password helps to increase the time and resources required to compromise the password. Application servers provide either a local user store or they integrate with enterprise user stores like LDAP. When the AS provides the user store and enforces authentication, the AS must enforce the organizations password complexity requirements that includes the requirement to use a specific number of numeric characters when passwords are created or changed. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43684r1_chk ) |
---|
Review AS documentation and configuration to determine if the AS enforces the requirement that users utilize a configurable number of numeric characters when creating or changing their password. If the AS is not configured to meet this requirement, this is a finding. |
Fix Text (F-39860r1_fix) |
---|
Configure the AS to require users to utilize a specific number of numeric characters when creating or changing their passwords. |