Rule ID
SV-44862r1_rule
Version
V1R12
CCIs
Some common password hashing schemes only process the first eight characters of a user's password, which reduces the effective strength of the password.
Verify no password hash in /etc/passwd or /etc/shadow begins with a character other than an underscore (_) or dollar sign ($). # cut -d ':' -f2 /etc/passwd # cut -d ':' -f2 /etc/shadow If any password hash is present that does not have an initial underscore (_) or dollar sign ($) character, this is a finding.
Change the passwords for all accounts using non-compliant password hashes. (This requires GEN000590 is already met.)