Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-76963 | DBNW-DM-000057 | SV-91659r1_rule | Medium |
Description |
---|
Use of a complex passwords helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. Password complexity is one factor of several that determine how long it takes to crack a password. The more complex the password is, the greater the number of possible combinations that need to be tested before the password is compromised. |
STIG | Date |
---|---|
DBN-6300 NDM Security Technical Implementation Guide | 2017-09-15 |
Check Text ( C-76589r1_chk ) |
---|
To see if the system requires password complexity attempt to change your password to a non-conforming password. If the user is able to change their password without meeting the requirement, this is a finding. |
Fix Text (F-83659r1_fix) |
---|
Set the password-complexity variable within the DBN-6300 through the CLI. This value is set with the following registry entry in the CLI: reg set /sysconfig/auth/01 {"stores": {"local": {"policies": {"passwordQuality": {"owasp": {"enable": true,"allowPassphrases": false }}}}}} |