Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-50855 | OL6-00-000274 | SV-65061r4_rule | Medium |
Description |
---|
Preventing reuse of previous passwords helps ensure that a compromised password is not reused by a user. |
STIG | Date |
---|---|
Oracle Linux 6 Security Technical Implementation Guide | 2018-03-01 |
Check Text ( C-53327r4_chk ) |
---|
To verify the password reuse setting is compliant, run the following command: # grep remember /etc/pam.d/system-auth The output must be a line beginning with "password required pam_pwhistory.so" and ending with "remember=5". If the line is commented out, the line does not contain the specified elements, or the value for "remember" is less than 5, this is a finding. |
Fix Text (F-55649r6_fix) |
---|
Do not allow users to reuse recent passwords. This can be accomplished by using the "remember" option for the "pam_pwhistory" PAM module. In the file "/etc/pam.d/system-auth", append "remember=5" to the line which refers to the "pam_pwhistory.so" module, as shown: password required pam_pwhistory.so [existing_options] remember=5 The DoD requirement is five passwords. |