SV-100217r1_rule
V-89567
SRG-OS-000070-GPOS-00038
VRAU-SL-000350
CAT II
10
If "lcredit" was not set at all in /etc/pam.d/common-password-vmware.local then run the following command:
# sed -i '/pam_cracklib.so/ s/$/ lcredit=-1/' /etc/pam.d/common-password-vmware.local
If "lcredit" was set incorrectly then run the following command to set it to "-1":
# sed -i '/pam_cracklib.so/ s/lcredit=../lcredit=-1/' /etc/pam.d/common-password-vmware.local
Verify the SLES for vRealize enforces password complexity by requiring that at least one lower-case character be used by using the following command:
# grep lcredit /etc/pam.d/common-password-vmware.local
If "lcredit" is not set to "-1" or not at all, this is a finding.
Expected Result:
password requisite pam_cracklib.so dcredit=-1 ucredit=-1 lcredit=-1 ocredit=-1 minlen=14 difok=4 retry=3
V-89567
False
VRAU-SL-000350
Verify the SLES for vRealize enforces password complexity by requiring that at least one lower-case character be used by using the following command:
# grep lcredit /etc/pam.d/common-password-vmware.local
If "lcredit" is not set to "-1" or not at all, this is a finding.
Expected Result:
password requisite pam_cracklib.so dcredit=-1 ucredit=-1 lcredit=-1 ocredit=-1 minlen=14 difok=4 retry=3
M
3459