Set password creation requirement parameters using pam_cracklibID: oval:org.secpod.oval:def:46227 | Date: (C)2018-07-05 (M)2023-12-20 |
Class: COMPLIANCE | Family: unix |
The pam_cracklib module checks the strength of passwords. It performs checks such as making sure a password is not a dictionary word, it is a certain length, contains a mix of characters (e.g. alphabet, numeric, other) and more. The following are definitions of the pam_cracklib.so options.
* retry=3 - Allow 3 tries before sending back a failure.
* minlen=14 - password must be 14 characters or more
* dcredit=-1 - provide at least one digit
* ucredit=-1 - provide at least one uppercase character
* ocredit=-1 - provide at least one special character
* lcredit=-1 - provide at least one lowercase character
The setting shown above is one possible policy. Alter these values to conform to your own organization's password policies.