CCI-000192
The information system enforces password complexity by the minimum number of upper case characters used.
5 rules found Severity: Medium

6 rules found Severity: Medium

6 rules found Severity: Medium

1 rule found Severity: Medium

If multifactor authentication is not supported and passwords must be used, the Akamai Luna Portal must enforce password complexity by requiring that at least one upper-case character be used.
1 rule found Severity: Medium

If multifactor authentication is not supported and passwords must be used, the DBN-6300 must enforce password complexity by requiring that at least one upper-case character be used.
1 rule found Severity: Medium

The FortiGate device must enforce password complexity by requiring that at least one uppercase character be used.
1 rule found Severity: Medium

If multifactor authentication is not supported and passwords must be used, CounterACT must enforce password complexity by requiring that at least one upper-case character be used.
1 rule found Severity: Medium

If multifactor authentication is not supported and passwords must be used, the HP FlexFabric Switch must enforce password complexity by requiring that at least one upper-case character be used.
1 rule found Severity: Medium

The HYCU server must enforce password complexity by requiring that at least one uppercase character be used.
1 rule found Severity: Medium

If multifactor authentication is not supported and passwords must be used, the DataPower Gateway must enforce password complexity by requiring that at least one upper-case character be used.
1 rule found Severity: Medium

IBM Aspera Console must enforce password complexity by requiring at least fifteen characters, with at least one upper case letter, one lower case letter, one number, and one symbol.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The MQ Appliance network device must enforce password complexity by requiring that at least one upper-case character be used.
1 rule found Severity: Medium

The Ivanti MobileIron Core server must enforce password complexity by requiring that at least one uppercase character be used.
1 rule found Severity: Medium

MobileIron Sentry must enforce password complexity by requiring that at least one upper-case character be used.
1 rule found Severity: Medium

The Manager Web app password must be configured as follows: -15 or more characters -at least one lower case letter -at least one upper case letter -at least one number -at least one special character
1 rule found Severity: Medium

If SQL Server authentication, using passwords, is employed, SQL Server must enforce the DoD standards for password complexity.
1 rule found Severity: Medium

Nutanix AOS must enforce password complexity by requiring that at least one uppercase character be used.
1 rule found Severity: Medium

1 rule found Severity: Medium

Riverbed Optimization System (RiOS) must enforce password complexity by requiring that at least one upper-case character be used.
1 rule found Severity: Medium

The Ubuntu operating system must enforce password complexity by requiring that at least one upper-case character be used.
2 rules found Severity: Low

If DBMS authentication using passwords is employed, MongoDB must enforce the DoD standards for password complexity and lifetime.
1 rule found Severity: High

If passwords are used for authentication, MongoDB must implement LDAP or Kerberos for authentication to enforce the DoD standards for password complexity and lifetime.
1 rule found Severity: High

1 rule found Severity: Medium

The DBMS must support organizational requirements to prohibit password reuse for the organization-defined number of generations.
1 rule found Severity: Medium

The DBMS must support organizational requirements to enforce password complexity by the number of upper-case characters used.
1 rule found Severity: Medium

The DBMS must support organizational requirements to enforce password complexity by the number of lower-case characters used.
1 rule found Severity: Medium

The DBMS must support organizational requirements to enforce password complexity by the number of numeric characters used.
1 rule found Severity: Medium

The DBMS must support organizational requirements to enforce password complexity by the number of special characters used.
1 rule found Severity: Medium

The DBMS must support organizational requirements to enforce the number of characters that get changed when passwords are changed.
1 rule found Severity: Medium

Procedures for establishing temporary passwords that meet DoD password requirements for new accounts must be defined, documented, and implemented.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must be configured so that /etc/pam.d/passwd implements /etc/pam.d/system-auth when changing passwords.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must be configured so that when passwords are changed or new passwords are established, pwquality must be used.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must be configured so that when passwords are changed or new passwords are established, the new password must contain at least one upper-case character.
1 rule found Severity: Medium

If DBMS authentication, using passwords, is employed, EDB Postgres Advanced Server must enforce the DoD standards for password complexity and lifetime.
1 rule found Severity: High

If multifactor authentication is not supported and passwords must be used, the BIG-IP appliance must enforce password complexity by requiring that at least one upper-case character be used.
1 rule found Severity: Medium

The Cisco ASA must be configured to enforce password complexity by requiring that at least one uppercase character be used.
1 rule found Severity: Medium

For accounts using password authentication, the Cisco ISE must enforce password complexity by requiring that at least one uppercase character be used.
1 rule found Severity: Medium

If DBMS authentication, using passwords, is employed, EDB Postgres Advanced Server must enforce the DOD standards for password complexity and lifetime.
1 rule found Severity: High

The F5 BIG-IP appliance must enforce password complexity by requiring that at least one uppercase character be used.
1 rule found Severity: Medium

1 rule found Severity: High

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

If MarkLogic Server authentication using passwords is employed, MarkLogic Server must enforce the DOD standards for password complexity and lifetime.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The Oracle Linux operating system must be configured so that /etc/pam.d/passwd implements /etc/pam.d/system-auth when changing passwords.
1 rule found Severity: Medium

The Oracle Linux operating system must be configured so that when passwords are changed or new passwords are established, pwquality must be used.
1 rule found Severity: Medium

The Oracle Linux operating system must be configured so that when passwords are changed or new passwords are established, the new password must contain at least one upper-case character.
1 rule found Severity: Medium

If Database Management System (DBMS) authentication using passwords is employed, the DBMS must enforce the DOD standards for password complexity and lifetime.
1 rule found Severity: High

1 rule found Severity: Medium

If DBMS authentication using passwords is employed, Redis Enterprise DBMS must enforce the DOD standards for password complexity and lifetime.
1 rule found Severity: Medium

1 rule found Severity: Medium

Splunk Enterprise must enforce password complexity for the account of last resort by requiring that at least one uppercase character be used.
1 rule found Severity: Low

Splunk Enterprise must be configured to enforce password complexity by requiring that at least one uppercase character be used.
1 rule found Severity: Low

The TippingPoint SMS must enforce password complexity by requiring that at least one uppercase character be used.
1 rule found Severity: Medium

The macOS system must require passwords contain a minimum of one lowercase character and one uppercase character.
1 rule found Severity: Medium

The application must enforce password complexity by requiring that at least one uppercase character be used.
1 rule found Severity: Medium

Ubuntu 22.04 LTS must enforce password complexity by requiring at least one uppercase character be used.
1 rule found Severity: Medium

The Cisco switch must be configured to enforce password complexity by requiring that at least one uppercase character be used.
2 rules found Severity: Medium

The Cisco router must be configured to enforce password complexity by requiring that at least one uppercase character be used.
1 rule found Severity: Medium

Forescout must enforce password complexity by requiring that at least one uppercase character be used.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Juniper router must be configured to enforce password complexity by requiring that at least one uppercase character be used.
1 rule found Severity: Medium

For local accounts using password authentication (i.e., the root account and the account of last resort), the Juniper SRX Services Gateway must enforce password complexity by setting the password change type to character sets.
1 rule found Severity: Medium

For local accounts using password authentication (i.e., the root account and the account of last resort), the Juniper SRX Services Gateway must enforce password complexity by requiring at least one uppercase character be used.
1 rule found Severity: Medium

If MariaDB authentication, using passwords, is employed, then MariaDB must enforce the DOD standards for password complexity.
1 rule found Severity: High

If MariaDB authentication using passwords is employed, MariaDB must enforce the DOD standards for password lifetime.
1 rule found Severity: Medium

If DBMS authentication using passwords is employed, SQL Server must enforce the DOD standards for password complexity and lifetime.
1 rule found Severity: High

1 rule found Severity: Medium

1 rule found Severity: Medium

The DBMS must support organizational requirements to enforce password complexity by the number of uppercase characters used.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Low

If multifactor authentication is not available and passwords must be used, the Palo Alto Networks security platform must enforce password complexity by requiring that at least one uppercase character be used.
1 rule found Severity: Medium

1 rule found Severity: Medium

RHEL 9 must ensure the password complexity module in the system-auth file is configured for three retries or less.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

The NSX Manager must enforce password complexity by requiring that at least one uppercase character be used for local accounts.
1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

The Photon operating system must enforce password complexity by requiring that at least one uppercase character be used.
2 rules found Severity: Medium

3 rules found Severity: Medium

1 rule found Severity: Medium

Rancher MCM must use a centralized user management solution to support account management functions. For accounts using password authentication, the container platform must use FIPS-validated SHA-2 or later protocol to protect the integrity of the password authentication process.
1 rule found Severity: High
