1. Home
  2. Security Hardening
  3. DISA Red Hat Enterprise Linux 7 STIG V3R5
  4. RHEL-07-010118 – The Red Hat Enterprise Linux operating system must be configured so that /etc/pam.d/passwd implements /etc/pam.d/system-auth when changing passwords.

RHEL-07-010118 – The Red Hat Enterprise Linux operating system must be configured so that /etc/pam.d/passwd implements /etc/pam.d/system-auth when changing passwords.

Details

Pluggable authentication modules (PAM) allow for a modular approach to integrating authentication methods. PAM operates in a top-down processing model and if the modules are not listed in the correct order, an important security function could be bypassed if stack entries are not centralized.

Solution

Configure PAM to utilize /etc/pam.d/system-auth when changing passwords.

Add the following line to ‘/etc/pam.d/passwd’ (or modify the line to have the required value):

password substack system-auth

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Identification and Authentication.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles