Skip to content

The DBN-6300 must prohibit password reuse for a minimum of five generations.

An XCCDF Rule

Description

Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. To meet password policy requirements, passwords need to be changed at specific policy-based intervals. If the network device allows the user to consecutively reuse their password when that password has exceeded its defined lifetime, the end result is a password that is not changed as per policy requirements.

ID
SV-91657r1_rule
Version
DBNW-DM-000056
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Set a password-reuse variable within the DBN-6300 through the CLI.

This value is set with the following registry entry in the CLI:
reg set /sysconfig/auth/01 {"stores": {"local": {"policies": {"passwordReuse": {"check": true,"numberToKeep": 5 }}}}}