SV-209012r603263_rule
V-209012
SRG-OS-000077
OL6-00-000274
CAT II
10
Do not allow users to reuse recent passwords. This can be accomplished by using the "remember" option for the "pam_pwhistory" PAM module. In the file "/etc/pam.d/system-auth", append "remember=5" to the line which refers to the "pam_pwhistory.so" module, as shown:
password required pam_pwhistory.so [existing_options] remember=5
The DoD requirement is five passwords.
To verify the password reuse setting is compliant, run the following command:
# grep remember /etc/pam.d/system-auth /etc/pam.d/password-auth
The output must be a line beginning with "password required pam_pwhistory.so" and ending with "remember=5".
If the line is commented out, the line does not contain the specified elements, or the value for "remember" is less than “5”, this is a finding.
V-209012
False
OL6-00-000274
To verify the password reuse setting is compliant, run the following command:
# grep remember /etc/pam.d/system-auth /etc/pam.d/password-auth
The output must be a line beginning with "password required pam_pwhistory.so" and ending with "remember=5".
If the line is commented out, the line does not contain the specified elements, or the value for "remember" is less than “5”, this is a finding.
M
2928