STIGQter STIGQter: STIG Summary: VMware vRealize Automation 7.x SLES Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

User passwords must be changed at least every 60 days.

DISA Rule

SV-100233r1_rule

Vulnerability Number

V-89583

Group Title

SRG-OS-000076-GPOS-00044

Rule Version

VRAU-SL-000395

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Set the maximum time period between password changes for each [USER] account to "60" days. The command in the check text will give you a list of users that need to be updated to be in compliance.

# passwd -x 60 [USER]

The DoD requirement is "60" days.

Check Contents

Check the max days field of /etc/shadow by running the following command:

# cat /etc/shadow | cut -d':' -f1,5 | egrep -v "([0|60])" | grep -v ":$"

If any results are returned, this is a finding.

Vulnerability Number

V-89583

Documentable

False

Rule Version

VRAU-SL-000395

Severity Override Guidance

Check the max days field of /etc/shadow by running the following command:

# cat /etc/shadow | cut -d':' -f1,5 | egrep -v "([0|60])" | grep -v ":$"

If any results are returned, this is a finding.

Check Content Reference

M

Target Key

3459

Comments