STIGQter STIGQter: STIG Summary: VMware vRealize Automation 7.x SLES Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

The SLES for vRealize must prevent the use of dictionary words for passwords.

DISA Rule

SV-100515r1_rule

Vulnerability Number

V-89865

Group Title

SRG-OS-000480-GPOS-00225

Rule Version

VRAU-SL-001500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Edit "/etc/pam.d/common-password" and configure "pam_cracklib" by adding a line such as "password requisite pam_cracklib.so"

Check Contents

Check "/etc/pam.d/common-password" for "pam_cracklib" configuration:

# grep pam_cracklib /etc/pam.d/common-password*

If "pam_cracklib" is not present, this is a finding.

Ensure the "passwd" command uses the "common-password" settings.

# grep common-password /etc/pam.d/passwd

If a line "password include common-password" is not found then the "password checks in common-password" will not be applied to new passwords, this is a finding.

Vulnerability Number

V-89865

Documentable

False

Rule Version

VRAU-SL-001500

Severity Override Guidance

Check "/etc/pam.d/common-password" for "pam_cracklib" configuration:

# grep pam_cracklib /etc/pam.d/common-password*

If "pam_cracklib" is not present, this is a finding.

Ensure the "passwd" command uses the "common-password" settings.

# grep common-password /etc/pam.d/passwd

If a line "password include common-password" is not found then the "password checks in common-password" will not be applied to new passwords, this is a finding.

Check Content Reference

M

Target Key

3459

Comments