STIGQter STIGQter: STIG Summary: VMware vRealize Operations Manager 6.x SLES Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

The SLES for vRealize must prevent the use of dictionary words for passwords.

DISA Rule

SV-99411r1_rule

Vulnerability Number

V-88761

Group Title

SRG-OS-000480-GPOS-00225

Rule Version

VROM-SL-001480

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure SLES for vRealize to prevent the use of dictionary words for passwords.

Edit the file "/etc/pam.d/common-password". Configure "common-password" by adding a line such as:

password required pam_cracklib.so

Save the changes made to the file "/etc/pam.d/common-password".

Check Contents

Verify the module "pam_cracklib.so" is present.

Procedure:

# ls /lib/security/

Confirm that "pam_cracklib.so" is present in the directory listing.

If "pam_cracklib.so" is not present, this is a finding.

Verify the file "/etc/pam.d/common-password" is configured.

Procedure:

# grep pam_cracklib /etc/pam.d/common-password*

If a line containing "password required pam_cracklib.so" is not present, this is a finding.

Vulnerability Number

V-88761

Documentable

False

Rule Version

VROM-SL-001480

Severity Override Guidance

Verify the module "pam_cracklib.so" is present.

Procedure:

# ls /lib/security/

Confirm that "pam_cracklib.so" is present in the directory listing.

If "pam_cracklib.so" is not present, this is a finding.

Verify the file "/etc/pam.d/common-password" is configured.

Procedure:

# grep pam_cracklib /etc/pam.d/common-password*

If a line containing "password required pam_cracklib.so" is not present, this is a finding.

Check Content Reference

M

Target Key

3461

Comments