SLEM 5 must prevent the use of dictionary words for passwords.
An XCCDF Rule
Description
If SLEM 5 allows the user to select passwords based on dictionary words, this increases the chances of password compromise by increasing the opportunity for successful guesses and brute-force attacks.
- ID
- SV-261381r996574_rule
- Version
- SLEM-05-611030
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure SLEM 5 to prevent the use of dictionary words for passwords.
Edit "/etc/pam.d/common-password" and add the following line:
password requisite pam_cracklib.so