DISA STIGS Viewer

The operating system must enforce password complexity requiring that at least one lowercase character is used.

Overview

Finding ID Version Rule ID IA Controls Severity
V-216093 SOL-11.1-040080 SV-216093r1016288_rule   Medium
Description
Complex passwords can reduce the likelihood of success of automated password-guessing attacks.
STIG Date
Solaris 11 X86 Security Technical Implementation Guide 2024-11-25

Details

Check Text (C-17331r986435_chk)
Check the MINLOWER setting.

# grep ^MINLOWER /etc/default/passwd

If MINLOWER is not set to one or more, this is a finding.
Fix Text (F-17329r986436_fix)
The root role is required.

# pfedit /etc/default/passwd

Locate the line containing:

MINLOWER

Change the line to read:

MINLOWER=1