SV-100517r1_rule
V-89867
SRG-OS-000480-GPOS-00225
VRAU-SL-001505
CAT II
10
Configure the SLES for vRealize to prevent the use of dictionary words for passwords. Edit the file "/etc/pam.d/common-password". Configure "common-password" by adding a line such as:
password required pam_cracklib.so
Save the changes made to the file "/etc/pam.d/common-password".
Verify the module "pam_cracklib.so" is present.
# ls /lib/security/
Confirm that "pam_cracklib.so" is present in the directory listing.
If "pam_cracklib.so" is not present, this is a finding.
Verify the file "/etc/pam.d/common-password" is configured.
# grep pam_cracklib /etc/pam.d/common-password*
If a line containing "password required pam_cracklib.so" is not present, this is a finding.
V-89867
False
VRAU-SL-001505
Verify the module "pam_cracklib.so" is present.
# ls /lib/security/
Confirm that "pam_cracklib.so" is present in the directory listing.
If "pam_cracklib.so" is not present, this is a finding.
Verify the file "/etc/pam.d/common-password" is configured.
# grep pam_cracklib /etc/pam.d/common-password*
If a line containing "password required pam_cracklib.so" is not present, this is a finding.
M
3459