SV-100219r1_rule
V-89569
SRG-OS-000071-GPOS-00039
VRAU-SL-000355
CAT II
10
If "dcredit" was not set at all in /etc/pam.d/common-password-vmware.local, run the following command:
# sed -i '/pam_cracklib.so/ s/$/ dcredit=-1/' /etc/pam.d/common-password-vmware.local
If "dcredit" was set incorrectly, run the following command:
# sed -i '/pam_cracklib.so/ s/dcredit=../dcredit=-1/' /etc/pam.d/common-password-vmware.local
Check that the SLES for vRealize enforces password complexity by requiring that at least one numeric character be used by running the following command:
# grep dcredit /etc/pam.d/common-password-vmware.local
If "dcredit" is not set to "-1" or is not set at all, this is a finding.
Expected Result:
password requisite pam_cracklib.so dcredit=-1 ucredit=-1 lcredit=-1 ocredit=-1 minlen=14 difok=4 retry=3
V-89569
False
VRAU-SL-000355
Check that the SLES for vRealize enforces password complexity by requiring that at least one numeric character be used by running the following command:
# grep dcredit /etc/pam.d/common-password-vmware.local
If "dcredit" is not set to "-1" or is not set at all, this is a finding.
Expected Result:
password requisite pam_cracklib.so dcredit=-1 ucredit=-1 lcredit=-1 ocredit=-1 minlen=14 difok=4 retry=3
M
3459