UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The FortiGate device must enforce a minimum 15-character password length.


Overview

Finding ID Version Rule ID IA Controls Severity
V-234203 FGFW-ND-000220 SV-234203r879601_rule Medium
Description
Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. Password length is one factor of several that helps to determine strength and how long it takes to crack a password. The shorter the password, the lower the number of possible combinations that need to be tested before the password is compromised. Use of more characters in a password helps to exponentially increase the time and/or resources required to compromise the password.
STIG Date
Fortinet FortiGate Firewall NDM Security Technical Implementation Guide 2023-06-01

Details

Check Text ( C-37388r628879_chk )
Log in to the FortiGate GUI with Super-Admin privilege.

1. Click System.
2. Click Settings.
3. Navigate to Password Policy.
4. Verify Password scope is enabled for Admin.
5. Verify the Minimum length is set to 15.

If the Password scope is OFF and the Minimum length is not set to 15, this is a finding.

or

Log in to the FortiGate GUI with Super-Admin privilege:

1. Open a CLI console, via SSH or available from the GUI
2. Run the following command:
# show full-configuration system password-policy | grep -i minimum
set minimum-length 15

If the minimum-length parameter is not set to 15, this is a finding.
Fix Text (F-37353r611797_fix)
Log in to the FortiGate GUI with Super-Admin privilege.

1. Click System.
2. Click Settings.
3. Navigate to Password Policy.
4. On the Password scope option, click Admin.
5. Enter the Minimum length value of 15.

or

Log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# config system password-policy
# set status enable
# set minimum-length 15
# end--+