SV-238223r653844_rule
V-238223
SRG-OS-000071-GPOS-00039
UBTU-20-010052
CAT III
10
Configure the Ubuntu operating system to enforce password complexity by requiring that at least one numeric character be used.
Add or update the "/etc/security/pwquality.conf" file to contain the "dcredit" parameter:
dcredit=-1
Verify the Ubuntu operating system enforces password complexity by requiring that at least one numeric character be used.
Determine if the field "dcredit" is set in the "/etc/security/pwquality.conf" file with the following command:
$ grep -i "dcredit" /etc/security/pwquality.conf
dcredit=-1
If the "dcredit" parameter is greater than "-1" or is commented out, this is a finding.
V-238223
False
UBTU-20-010052
Verify the Ubuntu operating system enforces password complexity by requiring that at least one numeric character be used.
Determine if the field "dcredit" is set in the "/etc/security/pwquality.conf" file with the following command:
$ grep -i "dcredit" /etc/security/pwquality.conf
dcredit=-1
If the "dcredit" parameter is greater than "-1" or is commented out, this is a finding.
M
5318