Ensure PAM Enforces Password Requirements - Minimum Length
Set Password Minimum Length in login.defs
Ensure PAM Enforces Password Requirements - Enforce for root User
Set Password Minimum Length
AAA Services must be configured to enforce a minimum 15-character password length.
Compliance Guardian must provide automated mechanisms for supporting account management functions.
The Akamai Luna Portal must enforce a minimum 15-character password length.
Apple iOS/iPadOS 15 must be configured to enforce a minimum password length of six characters.
The Arista Multilayer Switch account of last resort must have a password with a length of 15 characters.
The Arista network device must enforce a minimum 15-character password length.
The application must enforce a minimum 15-character password length.
The CA API Gateway must enforce a minimum 15-character password length.
The Central Log Server must be configured to enforce a minimum 15-character password length.
The DBN-6300 must enforce a minimum 15-character password length.
The FortiGate device must enforce a minimum 15-character password length.
CounterACT must enforce a minimum 15-character password length.
Forescout must enforce a minimum 15-character password length.
Google Android 12 must be configured to enforce a minimum password length of six characters.
Google Android 13 must be configured to enforce a minimum password length of six characters.
The HP FlexFabric Switch must enforce a minimum 15-character password length.
The storage system must require passwords contain a minimum of 15 characters, after an administrator has set the minimum password length to that value.
The HYCU server must enforce password complexity by requiring that at least one uppercase character be used.
The network device must enforce a minimum 15-character password length.
The DataPower Gateway must enforce a minimum 15-character password length.
IBM Aspera Console must enforce password complexity by requiring at least fifteen characters, with at least one upper case letter, one lower case letter, one number, and one symbol.
The MQ Appliance network device must enforce a minimum 15-character password length.
IBM zVM CA VM:Secure product PASSWORD user exit must be in use.
The Ivanti MobileIron Core server must enforce a minimum 15-character password length.
MobileIron Sentry device must enforce a minimum 15-character password length.
The Manager Web app password must be configured as follows: -15 or more characters -at least one lower case letter -at least one upper case letter -at least one number -at least one special character
The Jamf Pro EMM local accounts password must be configured with length of 15 characters.
The Juniper router must be configured to enforce a minimum 15-character password length.
For local accounts using password authentication (i.e., the root account and the account of last resort), the Juniper SRX Services Gateway must enforce a minimum 15-character password length.
The Mainframe Product must enforce a minimum 15-character password length.
Microsoft Android 11 must be configured to enforce a minimum password length of six characters.
Motorola Solutions Android 11 must be configured to enforce a minimum password length of six characters.
If SQL Server authentication, using passwords, is employed, SQL Server must enforce the DoD standards for password complexity.
ONTAP must enforce a minimum 15-character password length.
Nutanix AOS must enforce a minimum 15 character password length.
Oracle WebLogic must enforce minimum password length.
Prisma Cloud Compute local accounts must enforce strong password requirements.
The Riverbed NetProfiler must be configured to enforce a minimum 15-character password length.
Riverbed Optimization System (RiOS) must enforce a minimum 15-character password length.
Samsung Android must be configured to enforce a minimum password length of six characters.
Splunk Enterprise must enforce a minimum 15-character password length for the account of last resort.
The Samsung SDS EMM local accounts password must be configured with length of 15 characters.
Symantec ProxySG must be configured to enforce a minimum 15-character password length for local accounts.
The Tanium application must enforce a minimum 15-character password length.
The TippingPoint SMS must enforce a minimum 15-character password length.
The Tanium Operating System (TanOS) must enforce a minimum 15-character password length.
The UEM server must enforce a minimum 15-character password length.
The NSX-T Manager must enforce a minimum 15-character password length.
The Workspace ONE UEM local accounts password must be configured with length of 15 characters.
The password values must be set to meet the requirements in accordance with DoDI 8500.2 for DoD information systems processing sensitive information and above, and CJCSI 6510.01E (INFORMATION ASSURANCE (IA) AND COMPUTER NETWORK DEFENSE (CND)).
Apple iOS/iPadOS 16 must be configured to enforce a minimum password length of six characters.
Apple iOS/iPadOS 17 must be configured to enforce a minimum password length of six characters.
The macOS system must enforce a minimum 15-character password length.
The macOS system must require a minimum password length of 14 characters.
The Ubuntu operating system must enforce a minimum 15-character password length.
The Cisco ASA must be configured to enforce a minimum 15-character password length.
The Cisco router must be configured to enforce a minimum 15-character password length.
The Cisco switch must be configured to enforce a minimum 15-character password length.
For accounts using password authentication, the Cisco ISE must enforce a minimum 15-character password length.
The container platform must enforce a minimum 15-character password length.
Google Android 13 must be configured to enforce a minimum password length of six characters and not allow passwords that include more than four repeating or sequential characters.
The HPE Nimble must enforce a minimum 15-character password length.
Google Android 14 must be configured to enforce a minimum password length of six characters.
The operating system must enforce a minimum 15-character password length.
SSMC must enforce a minimum 15-character password length.
The HPE 3PAR OS must be configured to enforce a minimum 15-character password length.
AIX must use Loadable Password Algorithm (LPA) password hashing algorithm.
AIX must enforce a minimum 15-character password length.
The IBM z/OS operating system must enforce a minimum eight-character password length.
The operating system must enforce a minimum 8-character password length.
IBM RACF PASSWORD(RULEn) SETROPTS value(s) must be properly set.
The ICS must be configured to enforce a minimum 15-character password length.
The Juniper EX switch must be configured to enforce a minimum 15-character password length.
Passwords must, at a minimum, be 14 characters.
Manually managed application account passwords must be at least 15 characters in length.
Windows Server 2016 minimum password length must be configured to 14 characters.
Windows Server 2019 manually managed application account passwords must be at least 15 characters in length.
Windows Server 2019 minimum password length must be configured to 14 characters.
Windows Server 2022 manually managed application account passwords must be at least 15 characters in length.
Windows Server 2022 minimum password length must be configured to 14 characters.
The DBMS must support organizational requirements to enforce minimum password length.
The Oracle Linux operating system must be configured so that passwords are a minimum of 15 characters in length.
OL 8 passwords must have a minimum of 15 characters.
OL 8 passwords for new users must have a minimum of 15 characters.
If multifactor authentication is not available and passwords must be used, the Palo Alto Networks security platform must enforce a minimum 15-character password length.
OpenShift must use FIPS validated LDAP or OpenIDConnect.
The Red Hat Enterprise Linux operating system must be configured so that passwords are a minimum of 15 characters in length.
RHEL 8 passwords must have a minimum of 15 characters.
RHEL 8 passwords for new users must have a minimum of 15 characters.
The SUSE operating system must employ passwords with a minimum of 15 characters.
RHEL 9 must enforce password complexity rules for the root account.
RHEL 9 passwords must be created with a minimum of 15 characters.
RHEL 9 passwords for new users must have a minimum of 15 characters.
User passwords must be at least 15 characters in length.
Splunk Enterprise must be configured to enforce a minimum 15-character password length.
The VMM must enforce a minimum 15-character password length.
The ESXi host must be configured with a sufficiently complex password policy.
The vCenter Server passwords must be at least 15 characters in length.
The ESXi host must enforce password complexity by configuring a password quality policy.
The Photon operating system must enforce a minimum eight-character password length.
The Photon operating system must enforce a minimum 15-character password length.
The BIG-IP appliance must be configured to enforce a minimum 15-character password length.
Ubuntu 22.04 LTS must enforce a minimum 15-character password length.
The Dragos Platform must configure local password policies.
The F5 BIG-IP appliance must enforce a minimum 15-character password length.
Google Android 14 must be configured to enforce a minimum password length of six characters and not allow passwords that include more than four repeating or sequential characters.
Sentry device must enforce a minimum 15-character password length.
MKE must be configured to integrate with an Enterprise Identity Provider.
Manually managed application account passwords must be at least 14 characters in length.
Windows Server 2019 manually managed application account passwords must be at least 14 characters in length.
Windows Server 2022 manually managed application account passwords must be at least 14 characters in length.
SLEM 5 must employ passwords with a minimum of 15 characters.
The NSX Manager must enforce a minimum 15-character password length for local accounts.