Skip to content

Nutanix AOS must prevent the use of dictionary words for passwords.

An XCCDF Rule

Description

If the operating system allows the user to select passwords based on dictionary words, then this increases the chances of password compromise by increasing the opportunity for successful guesses and brute-force attacks.

ID
SV-254192r846664_rule
Version
NUTX-OS-001050
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure Nutanix AOS to enforce the use of pam_pwquality.so by running the following command.

$ sudo salt-call state.sls security/CVM/pamCVM