SV-208835r603263_rule
V-208835
SRG-OS-000072
OL6-00-000060
CAT III
10
The pam_cracklib module's "difok" parameter controls requirements for usage of different characters during a password change.
Edit /etc/pam.d/system-auth and /etc/pam.d/password-auth adding "difok=[NUM]" after pam_cracklib.so to require differing characters when changing passwords, substituting [NUM] appropriately. The DoD requirement is “8”.
To check how many characters must differ during a password change, run the following command:
$ grep pam_cracklib /etc/pam.d/system-auth /etc/pam.d/password-auth
The "difok" parameter will indicate how many characters must differ. The DoD requires eight characters differ during a password change. This would appear as "difok=8".
If the “difok” parameter is not found or not set to the required value, this is a finding.
V-208835
False
OL6-00-000060
To check how many characters must differ during a password change, run the following command:
$ grep pam_cracklib /etc/pam.d/system-auth /etc/pam.d/password-auth
The "difok" parameter will indicate how many characters must differ. The DoD requires eight characters differ during a password change. This would appear as "difok=8".
If the “difok” parameter is not found or not set to the required value, this is a finding.
M
2928