Rule ID
SV-223218r1015753_rule
Version
V3R3
CCIs
CCI-004066, CCI-000192
Use of a complex passwords helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. The password change-type command specifies whether a minimum number of character-sets or a minimum number of character-set transitions are enforced. The DOD requires this setting be set to character-sets.
Verify the default local password enforces password complexity by setting the password change type to character sets. [edit] show system login password If the password change-type is not set to character-sets, this is a finding.
Configure the default local password to enforce password complexity by setting the password change type to character sets. [edit] set system login password change-type character-sets