Rule ID
SV-216365r959010_rule
Version
V3R5
CCIs
If the password field is blank and the system does not enforce a policy that passwords are required, it could allow login without proper authentication of a user.
Determine if the system is enforcing a policy that passwords are required. # grep ^PASSREQ /etc/default/login If the command does not return: PASSREQ=YES this is a finding.
The root role is required. Modify the /etc/default/login file. # pfedit /etc/default/login Insert the line: PASSREQ=YES