UCF STIG Viewer Logo

The application server must enforce the number of characters that get changed when passwords are changed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35316 SRG-APP-000170-AS-000118 SV-46603r1_rule Medium
Description
Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. Use of a complex password helps to increase the time and resources required to compromise the password. Application servers provide either a local user store or they integrate with enterprise user stores like LDAP. When the AS provides the user store and enforces authentication, the AS must enforce the organization's password complexity requirements, which includes the requirement to enforce the number of characters that get changed when passwords are changed.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43686r1_chk )
Review AS documentation and configuration to determine if the AS enforces the requirement to enforce the number of characters that get changed when passwords are changed. If the AS is not configured to meet this requirement, this is a finding.
Fix Text (F-39862r1_fix)
Configure the AS to enforce the number of characters that get changed when passwords are changed.