Back

Configure the "Password Creation Requirement" settings for "pam_cracklib" to organizational standards.


CONTROL ID
09953
CONTROL TYPE
Configuration
CLASSIFICATION
Preventive

SUPPORTING AND SUPPORTED CONTROLS




This Control directly supports the implied Control(s):
  • Configure Red Hat Enterprise Linux to Organizational Standards., CC ID: 08713

There are no implementation support Controls.


SELECTED AUTHORITY DOCUMENTS COMPLIED WITH




  • Ensure password creation requirements are configured Description: The `pam_pwquality.so` module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeric, other) and more.… (5.4.1, CIS Amazon Linux 2 Benchmark, v.2.0.0, Level 1)
  • Ensure password creation requirements are configured Description: The `pam_pwquality.so` module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeric, other) and more.… (5.4.1, CIS Amazon Linux 2 Benchmark, v.2.0.0, Level 2)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeric… (Rule: xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_6.3.2.1_, The Center for Internet Security CentOS 6 Level 1 Benchmark, 1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeric… (Rule: xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_6.3.2.2_, The Center for Internet Security CentOS 6 Level 1 Benchmark, 1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeric… (Rule: xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_6.3.2.3_, The Center for Internet Security CentOS 6 Level 1 Benchmark, 1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeric… (Rule: xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_6.3.2.4_, The Center for Internet Security CentOS 6 Level 1 Benchmark, 1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeric… (Rule: xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_6.3.2.5_, The Center for Internet Security CentOS 6 Level 1 Benchmark, 1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeric… (Rule: xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_6.3.2.6_, The Center for Internet Security CentOS 6 Level 1 Benchmark, 1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeric… (Rule: xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_6.3.2.7_, The Center for Internet Security CentOS 6 Level 1 Benchmark, 1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule:xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression:xccdf_org.cisecurity.benchmarks_ae_6.3.2.1_, The Center for Internet Security Red Hat Enterprise Linux 6 Level 1 Benchmark, 1.2.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule:xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression:xccdf_org.cisecurity.benchmarks_ae_6.3.2.2_, The Center for Internet Security Red Hat Enterprise Linux 6 Level 1 Benchmark, 1.2.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule:xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression:xccdf_org.cisecurity.benchmarks_ae_6.3.2.3_, The Center for Internet Security Red Hat Enterprise Linux 6 Level 1 Benchmark, 1.2.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule:xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression:xccdf_org.cisecurity.benchmarks_ae_6.3.2.4_, The Center for Internet Security Red Hat Enterprise Linux 6 Level 1 Benchmark, 1.2.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule:xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression:xccdf_org.cisecurity.benchmarks_ae_6.3.2.5_, The Center for Internet Security Red Hat Enterprise Linux 6 Level 1 Benchmark, 1.2.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule:xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression:xccdf_org.cisecurity.benchmarks_ae_6.3.2.6_, The Center for Internet Security Red Hat Enterprise Linux 6 Level 1 Benchmark, 1.2.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule:xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression:xccdf_org.cisecurity.benchmarks_ae_6.3.2.7_, The Center for Internet Security Red Hat Enterprise Linux 6 Level 1 Benchmark, 1.2.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule:xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression:xccdf_org.cisecurity.benchmarks_ae_6.3.2.1_, The Center for Internet Security Red Hat Enterprise Linux 6 Level 2 Benchmark, 1.2.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule:xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression:xccdf_org.cisecurity.benchmarks_ae_6.3.2.2_, The Center for Internet Security Red Hat Enterprise Linux 6 Level 2 Benchmark, 1.2.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule:xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression:xccdf_org.cisecurity.benchmarks_ae_6.3.2.3_, The Center for Internet Security Red Hat Enterprise Linux 6 Level 2 Benchmark, 1.2.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule:xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression:xccdf_org.cisecurity.benchmarks_ae_6.3.2.4_, The Center for Internet Security Red Hat Enterprise Linux 6 Level 2 Benchmark, 1.2.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule:xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression:xccdf_org.cisecurity.benchmarks_ae_6.3.2.5_, The Center for Internet Security Red Hat Enterprise Linux 6 Level 2 Benchmark, 1.2.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule:xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression:xccdf_org.cisecurity.benchmarks_ae_6.3.2.6_, The Center for Internet Security Red Hat Enterprise Linux 6 Level 2 Benchmark, 1.2.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks of the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule:xccdf_org.cisecurity.benchmarks_rule_6.3.2_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression:xccdf_org.cisecurity.benchmarks_ae_6.3.2.7_, The Center for Internet Security Red Hat Enterprise Linux 6 Level 2 Benchmark, 1.2.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule: xccdf_org.cisecurity.benchmarks_rule_9.2.1_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_9.2.1.1_, The Center for Internet Security Ubuntu 12.04 LTS Level 1 Benchmark, v1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule: xccdf_org.cisecurity.benchmarks_rule_9.2.1_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_9.2.1.2_, The Center for Internet Security Ubuntu 12.04 LTS Level 1 Benchmark, v1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule: xccdf_org.cisecurity.benchmarks_rule_9.2.1_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_9.2.1.3_, The Center for Internet Security Ubuntu 12.04 LTS Level 1 Benchmark, v1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule: xccdf_org.cisecurity.benchmarks_rule_9.2.1_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_9.2.1.4_, The Center for Internet Security Ubuntu 12.04 LTS Level 1 Benchmark, v1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule: xccdf_org.cisecurity.benchmarks_rule_9.2.1_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_9.2.1.5_, The Center for Internet Security Ubuntu 12.04 LTS Level 1 Benchmark, v1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule: xccdf_org.cisecurity.benchmarks_rule_9.2.1_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_9.2.1.6_, The Center for Internet Security Ubuntu 12.04 LTS Level 1 Benchmark, v1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule: xccdf_org.cisecurity.benchmarks_rule_9.2.1_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_9.2.1.1_, The Center for Internet Security Ubuntu 12.04 LTS Level 2 Benchmark, v1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule: xccdf_org.cisecurity.benchmarks_rule_9.2.1_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_9.2.1.2_, The Center for Internet Security Ubuntu 12.04 LTS Level 2 Benchmark, v1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule: xccdf_org.cisecurity.benchmarks_rule_9.2.1_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_9.2.1.3_, The Center for Internet Security Ubuntu 12.04 LTS Level 2 Benchmark, v1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule: xccdf_org.cisecurity.benchmarks_rule_9.2.1_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_9.2.1.4_, The Center for Internet Security Ubuntu 12.04 LTS Level 2 Benchmark, v1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule: xccdf_org.cisecurity.benchmarks_rule_9.2.1_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_9.2.1.5_, The Center for Internet Security Ubuntu 12.04 LTS Level 2 Benchmark, v1.0.0)
  • Title: Set Password Creation Requirement Parameters Using pam_cracklib Description: The pam_cracklib module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeri… (Rule: xccdf_org.cisecurity.benchmarks_rule_9.2.1_Set_Password_Creation_Requirement_Parameters_Using_pam_cracklib Artifact Expression: xccdf_org.cisecurity.benchmarks_ae_9.2.1.6_, The Center for Internet Security Ubuntu 12.04 LTS Level 2 Benchmark, v1.0.0)
  • Ensure password creation requirements are configured Description: The pam_pwquality.so module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeric, other) and more. T… (5.4.1, CIS Oracle Linux 8 Benchmark, Server Level 1, v1.0.1)
  • Ensure password creation requirements are configured Description: The pam_pwquality.so module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeric, other) and more. T… (5.4.1, CIS Oracle Linux 8 Benchmark, Server Level 2, v1.0.1)