CCI-000195
The information system, for password-based authentication, when new passwords are created, enforces that at least an organization-defined number of characters are changed.
4 rules found Severity: Medium

Ensure PAM Enforces Password Requirements - Maximum Consecutive Repeating Characters from Same Character Class
4 rules found Severity: Medium

6 rules found Severity: Medium

1 rule found Severity: Medium

If multifactor authentication is not supported and passwords must be used, the CA API Gateway must require that when a password is changed, the characters are changed in at least 8 of the positions within the password.
1 rule found Severity: Medium

The FortiGate device must require that when a password is changed, the characters are changed in at least eight of the positions within the password.
1 rule found Severity: Medium

The HYCU server must require that when a password is changed, the characters are changed in at least eight of the positions within the password.
1 rule found Severity: Medium

If SQL Server authentication, using passwords, is employed, SQL Server must enforce the DoD standards for password complexity.
1 rule found Severity: Medium

Nutanix AOS must require the change of at least 50 percent of the total number of characters when passwords are changed.
1 rule found Severity: Medium

1 rule found Severity: Medium

Nutanix AOS must require the maximum number of repeating characters be limited to three when passwords are changed.
1 rule found Severity: Medium

Nutanix AOS must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.
1 rule found Severity: Medium

Riverbed Optimization System (RiOS) must require that when a password is changed, the characters are changed in at least 15 of the positions within the password.
1 rule found Severity: Medium

Innoslate must use multifactor authentication for network access to privileged and non-privileged accounts.
1 rule found Severity: High

The Ubuntu operating system must require the change of at least 8 characters when passwords are changed.
2 rules found Severity: Low

The Red Hat Enterprise Linux operating system must be configured so that when passwords are changed a minimum of eight of the total number of characters must be changed.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must be configured so that when passwords are changed a minimum of four character classes must be changed.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must be configured so that when passwords are changed the number of repeating consecutive characters must not be more than three characters.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must be configured so that when passwords are changed the number of repeating characters of the same character class must not be more than four characters.
1 rule found Severity: Medium

If multifactor authentication is not supported and passwords must be used, the BIG-IP appliance must require that when a password is changed, the characters are changed in at least eight (8) of the positions within the password.
1 rule found Severity: Medium

Apple iOS/iPadOS 17 must be configured to not allow passwords that include more than four repeating or sequential characters.
2 rules found Severity: Medium

The Cisco ASA must be configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password.
1 rule found Severity: Medium

The F5 BIG-IP appliance must require that when a password is changed, the characters are changed in at least eight of the positions within the password.
1 rule found Severity: Medium

AIX must require the change of at least 50% of the total number of characters when passwords are changed.
1 rule found Severity: High

The Juniper EX switch must be configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Oracle Linux operating system must be configured so that when passwords are changed a minimum of eight of the total number of characters must be changed.
1 rule found Severity: Medium

The Oracle Linux operating system must be configured so that when passwords are changed a minimum of four character classes must be changed.
1 rule found Severity: Medium

The Oracle Linux operating system must be configured so that when passwords are changed the number of repeating consecutive characters must not be more than three characters.
1 rule found Severity: Medium

The Oracle Linux operating system must be configured so that when passwords are changed the number of repeating characters of the same character class must not be more than four characters.
1 rule found Severity: Medium

1 rule found Severity: Medium

SLEM 5 must require the change of at least eight of the total number of characters when passwords are changed.
1 rule found Severity: Medium

Samsung Android must be configured to not allow passwords that include more than four repeating or sequential characters.
3 rules found Severity: Medium

The application must require the change of at least eight of the total number of characters when passwords are changed.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Cisco switch must be configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password.
1 rule found Severity: Medium

The Cisco router must be configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password.
1 rule found Severity: Medium

1 rule found Severity: Medium

Forescout must require that when a password is changed, the characters are changed in at least eight of the positions within the password.
1 rule found Severity: Low

AOS must require that when a password is changed, the characters are changed in at least eight of the positions within the password.
1 rule found Severity: Medium

The DBMS must support organizational requirements to enforce the number of characters that get changed when passwords are changed.
1 rule found Severity: Medium

Access to Prisma Cloud Compute must be managed based on user need and least privileged using external identity providers for authentication and grouping to role-based assignments when possible.
1 rule found Severity: Medium

OL 8 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.
1 rule found Severity: Medium

OL 8 must require the maximum number of repeating characters be limited to three when passwords are changed.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Low

If multifactor authentication is not available and passwords must be used, the Palo Alto Networks security platform must require that when a password is changed, the characters are changed in at least 8 of the positions within the password.
1 rule found Severity: Medium

RHEL 8 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.
1 rule found Severity: Medium

RHEL 8 must require the maximum number of repeating characters be limited to three when passwords are changed.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

RHEL 9 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.
1 rule found Severity: Medium

RHEL 9 must require the maximum number of repeating characters be limited to three when passwords are changed.
1 rule found Severity: Medium

1 rule found Severity: Medium

The SUSE operating system must require the change of at least eight (8) of the total number of characters when passwords are changed.
1 rule found Severity: Medium

The SUSE operating system must require the change of at least eight of the total number of characters when passwords are changed.
1 rule found Severity: Medium

The system must require at least eight characters be changed between the old and new passwords during a password change.
2 rules found Severity: Medium

The NSX Manager must require that when a password is changed, the characters are changed in at least eight of the positions within the password.
1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

The Photon operating system must require that new passwords are at least four characters different from the old password.
1 rule found Severity: Medium

The Photon operating system must require the change of at least eight characters when passwords are changed.
1 rule found Severity: Medium

Rancher MCM must use a centralized user management solution to support account management functions. For accounts using password authentication, the container platform must use FIPS-validated SHA-2 or later protocol to protect the integrity of the password authentication process.
1 rule found Severity: High
