STIGQter STIGQter: STIG Summary: VMware vRealize Automation 7.x SLES Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

Users must not be able to change passwords more than once every 24 hours.

DISA Rule

SV-100229r1_rule

Vulnerability Number

V-89579

Group Title

SRG-OS-000075-GPOS-00043

Rule Version

VRAU-SL-000385

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Change the minimum time period between password changes for each [USER] account to 1 day. The command in the check text will give you a list of users that need to be updated to be in compliance.

# passwd -n 1 [USER]

Check Contents

Check the minimum time period between password changes for each user account is 1 day.

# cat /etc/shadow | cut -d ':' -f1,4 | grep -v 1 | grep -v ":$"

If any results are returned, this is a finding.

Vulnerability Number

V-89579

Documentable

False

Rule Version

VRAU-SL-000385

Severity Override Guidance

Check the minimum time period between password changes for each user account is 1 day.

# cat /etc/shadow | cut -d ':' -f1,4 | grep -v 1 | grep -v ":$"

If any results are returned, this is a finding.

Check Content Reference

M

Target Key

3459

Comments