Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
RHEL-06-000293 | RHEL-06-000293 | RHEL-06-000293_rule | Medium |
Description |
---|
Preventing re-use of previous passwords helps ensure that a compromised password is not re-used by a user. |
STIG | Date |
---|---|
Red Hat Enterprise Linux 6 Security Technical Implementation Guide | 2013-02-05 |
Check Text ( C-RHEL-06-000293_chk ) |
---|
To verify the password reuse setting is compliant, run the following command: $ grep remember /etc/pam.d/system-auth The output should show the following at the end of the line: remember=24 If it does not, this is a finding. |
Fix Text (F-RHEL-06-000293_fix) |
---|
Do not allow users to reuse recent passwords. This can be accomplished by using the "remember" option for the "pam_unix" PAM module. In the file "/etc/pam.d/system-auth", append "remember=24" to the line which refers to the "pam_unix.so" module, as shown: password sufficient pam_unix.so [existing_options] remember=24 The DoD requirement is 24 passwords. |