SV-100235r1_rule
V-89585
SRG-OS-000077-GPOS-00045
VRAU-SL-000400
CAT II
10
Configure pam to use password history.
If "remember" was not set at all in /etc/pam.d/common-password-vmware.local, run the following command:
# sed -i '/pam_cracklib.so/ s/$/ remember=5/' /etc/pam.d/common-password-vmware.local
If "remember" was set incorrectly, run the following command to set it to "5":
# sed -i '/pam_cracklib.so/ s/remember=./remember=5/' /etc/pam.d/common-password-vmware.local
Verify that the SLES for vRealize prohibits the reuse of a password for a minimum of five generations by running the following commands:
# grep pam_pwhistory.so /etc/pam.d/common-password-vmware.local
If the "remember" option in /etc/pam.d/common-password-vmware.local is not "5" or greater, this is a finding.
V-89585
False
VRAU-SL-000400
Verify that the SLES for vRealize prohibits the reuse of a password for a minimum of five generations by running the following commands:
# grep pam_pwhistory.so /etc/pam.d/common-password-vmware.local
If the "remember" option in /etc/pam.d/common-password-vmware.local is not "5" or greater, this is a finding.
M
3459