5.3.3.2.1 Ensure password number of changed characters is configured (Automated)
Profile Applicability
- Level 1 - Server
- Level 1 - Workstation
Description
The pwquality difok option sets the number of characters in a password that must not be present in the old password.
Rationale
Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks.
Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that need to be tested before the password is compromised.
Audit Procedure
Command Line
Run the following command to verify that the difok option is set to 2 or more and follows local site policy:
# grep -Psi -- '^\h*difok\h*=\h*([2-9]|[1-9][0-9]+)\b' /etc/security/pwquality.conf /etc/security/pwquality.conf.d/*.conf
Example output:
/etc/security/pwquality.conf.d/50-pwdifok.conf:difok = 2
Verify returned value(s) are 2 or more and meet local site policy.
Run the following command to verify that difok is not set, is 2 or more, and conforms to local site policy:
grep -Psi -- '^\h*password\h+(requisite|required|sufficient)\h+pam_pwquality\.so\h+([^#\n\r]+\h+)?difok\h*=\h*([0-1])\b' /etc/pam.d/common-password
Nothing should be returned.
Note:
- settings should be configured in only one location for clarity
- Settings observe an order of precedence:
- module arguments override the settings in the
/etc/security/pwquality.confconfiguration file - settings in the
/etc/security/pwquality.confconfiguration file override settings in a.conffile in the/etc/security/pwquality.conf.d/directory - settings in a
.conffile in the/etc/security/pwquality.conf.d/directory are read in canonical order, with last read file containing the setting taking precedence
- module arguments override the settings in the
- It is recommended that settings be configured in a
.conffile in the/etc/security/pwquality.conf.d/directory for clarity, convenience, and durability.
Remediation
Command Line
Create or modify a file ending in .conf in the /etc/security/pwquality.conf.d/ directory or the file /etc/security/pwquality.conf and add or modify the following line to set difok to 2 or more. Ensure setting conforms to local site policy:
Example:
#!/usr/bin/env bash
{
sed -ri 's/^\s*difok\s*=/# &/' /etc/security/pwquality.conf
[ ! -d /etc/security/pwquality.conf.d/ ] && mkdir /etc/security/pwquality.conf.d/
printf '\n%s' "difok = 2" > /etc/security/pwquality.conf.d/50-pwdifok.conf
}
Run the following command:
# grep -Pl -- '\bpam_pwquality\.so\h+([^#\n\r]+\h+)?difok\b' /usr/share/pam-configs/*
Edit any returned files and remove the difok argument from the pam_pwquality.so line(s).
Default Value
difok = 1
References
- NIST SP 800-53 Rev. 5: IA-5
CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 5.2 Use Unique Passwords | * | * | * |
| v7 | 4.4 Use Unique Passwords | * | * |
MITRE ATT&CK Mappings
| Techniques / Sub-techniques | Tactics | Mitigations |
|---|---|---|
| T1110, T1110.001, T1110.002, T1110.003, T1178.001, T1178.002, T1178.003, T1178.004 | TA0006 | M1027 |