SV-238325r654150_rule
V-238325
SRG-OS-000120-GPOS-00061
UBTU-20-010404
CAT II
10
Configure the Ubuntu operating system to encrypt all stored passwords.
Edit/modify the following line in the "/etc/login.defs" file and set "ENCRYPT_METHOD" to SHA512:
ENCRYPT_METHOD SHA512
Verify that the shadow password suite configuration is set to encrypt passwords with a FIPS 140-2 approved cryptographic hashing algorithm.
Check the hashing algorithm that is being used to hash passwords with the following command:
$ cat /etc/login.defs | grep -i encrypt_method
ENCRYPT_METHOD SHA512
If "ENCRYPT_METHOD" does not equal SHA512 or greater, this is a finding.
V-238325
False
UBTU-20-010404
Verify that the shadow password suite configuration is set to encrypt passwords with a FIPS 140-2 approved cryptographic hashing algorithm.
Check the hashing algorithm that is being used to hash passwords with the following command:
$ cat /etc/login.defs | grep -i encrypt_method
ENCRYPT_METHOD SHA512
If "ENCRYPT_METHOD" does not equal SHA512 or greater, this is a finding.
M
5318