Skip to content

Verify Proper Storage and Existence of Password Hashes

An XCCDF Group

Description

By default, password hashes for local accounts are stored in the second field (colon-separated) in /etc/shadow. This file should be readable only by processes running with root credentials, preventing users from casually accessing others' password hashes and attempting to crack them. However, it remains possible to misconfigure the system and store password hashes in world-readable files such as /etc/passwd, or to even store passwords themselves in plaintext on the system. Using system-provided tools for password change/creation should allow administrators to avoid such misconfiguration.

ID
xccdf_org.ssgproject.content_group_password_storage
Child Items
Updated