SV-99123r1_rule
V-88473
SRG-OS-000077-GPOS-00045
VROM-SL-000395
CAT II
10
Configure pam to use password history.
If the "remember" option was not set at all in "/etc/pam.d/common-password-vmware.local" file then run the following command:
# sed -i '/pam_cracklib.so/ s/$/ remember=5/' /etc/pam.d/common-password-vmware.local
If "remember" option was set incorrectly, run the following command to set it to "5":
# sed -i '/pam_cracklib.so/ s/remember=./remember=5/' /etc/pam.d/common-password-vmware.local
Verify that SLES for vRealize prohibits the reuse of a password for a minimum of five generations, by running the following commands:
# grep pam_pwhistory.so /etc/pam.d/common-password-vmware.local
If the "remember" option in "/etc/pam.d/common-password-vmware.local" file is not "5" or greater, this is a finding.
V-88473
False
VROM-SL-000395
Verify that SLES for vRealize prohibits the reuse of a password for a minimum of five generations, by running the following commands:
# grep pam_pwhistory.so /etc/pam.d/common-password-vmware.local
If the "remember" option in "/etc/pam.d/common-password-vmware.local" file is not "5" or greater, this is a finding.
M
3461