SV-239097r675099_rule
V-239097
SRG-OS-000073-GPOS-00041
PHTN-67-000025
CAT II
10
Open /etc/pam.d/system-password with a text editor.
Add the following argument (sha512) to the password line:
password required pam_unix.so sha512 shadow try_first_pass
At the command line, execute the following command:
# grep password /etc/pam.d/system-password|grep --color=always "sha512"
If the output does not include "sha512", this is a finding.
V-239097
False
PHTN-67-000025
At the command line, execute the following command:
# grep password /etc/pam.d/system-password|grep --color=always "sha512"
If the output does not include "sha512", this is a finding.
M
5323