Skip to content

The web server must, for password-based authentication, store passwords using an approved salted key derivation function, preferably using a keyed hash.

An XCCDF Rule