Rule ID
SV-223223r1056174_rule
Version
V3R3
CCIs
CCI-000197
Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised.
Verify the default local password enforces this requirement by entering the following in configuration mode. [edit] show system login password If the password format is not set to SHA256 or higher, this is a finding.
Enter the following example command from the configuration mode. [edit] set system login password format sha256