RHEL 8 user account passwords must have a 60-day maximum password lifetime restriction.
An XCCDF Rule
Description
Any password, no matter how complex, can eventually be cracked. Therefore, passwords need to be changed periodically. If RHEL 8 does not limit the lifetime of passwords and force users to change their passwords, there is the risk that RHEL 8 passwords could be compromised.
- ID
- SV-230366r1038967_rule
- Version
- RHEL-08-020200
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure RHEL 8 to enforce a 60-day maximum password lifetime.
Add, or modify the following line in the "/etc/login.defs" file:
PASS_MAX_DAYS 60