Skip to content

Protect Accounts by Restricting Password-Based Login

An XCCDF Group

Description

Conventionally, Unix shell accounts are accessed by providing a username and password to a login program, which tests these values for correctness using the /etc/passwd and /etc/shadow files. Password-based login is vulnerable to guessing of weak passwords, and to sniffing and man-in-the-middle attacks against passwords entered over a network or at an insecure console. Therefore, mechanisms for accessing accounts by entering usernames and passwords should be restricted to those which are operationally necessary.

ID
xccdf_org.ssgproject.content_group_accounts-restrictions
Child Items
Updated