UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

SLEM 5 must employ a password history file.


Overview

Finding ID Version Rule ID IA Controls Severity
V-261390 SLEM-05-611075 SV-261390r996595_rule Medium
Description
Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. If the information system or application allows the user to consecutively reuse their password when that password has exceeded its defined lifetime, the end result is a password that is not changed as per policy requirements.
STIG Date
SUSE Linux Enterprise Micro (SLEM) 5 Security Technical Implementation Guide 2024-06-04

Details

Check Text ( C-65119r996035_chk )
Verify the password history file exists on SLEM 5 with the following command:

> ls -al /etc/security/opasswd
-rw------- 1 root root 82 Dec 7 19:41 /etc/security/opasswd

If the "/etc/security/opasswd" file does not exist, this is a finding.
Fix Text (F-65027r996594_fix)
Configure SLEM 5 to create the password history file with the following commands:

Create the file:
> sudo touch /etc/security/opasswd

Set ownership permissions:
> sudo chown root:root /etc/security/opasswd

Set access permissions:
> sudo chmod 0600 /etc/security/opasswd