Do not allow users to reuse recent passwords. This can be accomplished by using the
remember
option for the pam_pwhistory
PAM module.
On systems with newer versions of authselect
, the pam_pwhistory
PAM module
can be enabled via authselect feature:
authselect enable-feature with-pwhistory
Otherwise, it should be enabled using an authselect custom profile.
Newer systems also have the /etc/security/pwhistory.conf
file for setting
pam_pwhistory
module options. This file should be used whenever available.
Otherwise, the pam_pwhistory
module options can be set in PAM files.
The value for remember
option must be equal or greater than