SV-204420r603261_rule
V-204420
SRG-OS-000076-GPOS-00044
RHEL-07-010250
CAT II
10
Configure the operating system to enforce a 60-day maximum password lifetime restriction.
Add the following line in "/etc/login.defs" (or modify the line to have the required value):
PASS_MAX_DAYS 60
If passwords are not being used for authentication, this is Not Applicable.
Verify the operating system enforces a 60-day maximum password lifetime restriction for new user accounts.
Check for the value of "PASS_MAX_DAYS" in "/etc/login.defs" with the following command:
# grep -i pass_max_days /etc/login.defs
PASS_MAX_DAYS 60
If the "PASS_MAX_DAYS" parameter value is not 60 or less, or is commented out, this is a finding.
V-204420
False
RHEL-07-010250
If passwords are not being used for authentication, this is Not Applicable.
Verify the operating system enforces a 60-day maximum password lifetime restriction for new user accounts.
Check for the value of "PASS_MAX_DAYS" in "/etc/login.defs" with the following command:
# grep -i pass_max_days /etc/login.defs
PASS_MAX_DAYS 60
If the "PASS_MAX_DAYS" parameter value is not 60 or less, or is commented out, this is a finding.
M
2899