STIGQter STIGQter: STIG Summary: Oracle Linux 6 Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 23 Apr 2021:

Users must be warned 7 days in advance of password expiration.

DISA Rule

SV-208829r603263_rule

Vulnerability Number

V-208829

Group Title

SRG-OS-000480

Rule Version

OL6-00-000054

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

To specify how many days prior to password expiration that a warning will be issued to users, edit the file "/etc/login.defs" and add or correct the following line, replacing [DAYS] appropriately:

PASS_WARN_AGE [DAYS]

The DoD requirement is 7.

Check Contents

To check the password warning age, run the command:

$ grep PASS_WARN_AGE /etc/login.defs

The DoD requirement is 7.
If it is not set to the required value, this is a finding.

Vulnerability Number

V-208829

Documentable

False

Rule Version

OL6-00-000054

Severity Override Guidance

To check the password warning age, run the command:

$ grep PASS_WARN_AGE /etc/login.defs

The DoD requirement is 7.
If it is not set to the required value, this is a finding.

Check Content Reference

M

Target Key

2928

Comments