Rule ID
SV-255554r984095_rule
Version
V1R2
CCIs
CCI-000192
Use of a complex passwords helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. Password complexity is one factor of several that determine how long it takes to crack a password. The more complex the password is, the greater the number of possible combinations that need to be tested before the password is compromised.
To see if the system requires password complexity attempt to change your password to a non-conforming password. If the user is able to change their password without meeting the requirement, this is a finding.
Set the password-complexity variable within the DBN-6300 through the CLI.
This value is set with the following registry entry in the CLI:
reg set /sysconfig/auth/01 {"stores": {"local": {"policies": {"passwordQuality": {"owasp": {"enable": true,"allowPassphrases": false }}}}}}