Techskills Linuxsecurity 1 3 Auditing User Passwords
Techskills Linuxsecurity 1 3 Auditing User Passwords
============================================================
Filename: techskills-linuxsecurity-1-3-auditing_user_passwords
Title: Auditing User Passwords
Subtitle: Linux Security Techniques
Password complexity
/etc/security/pwquality.conf
minlen- Password length (in credits)
lcredit - Lower case characters
ucredit - Upper case characters
ocredit - Other characters
dcredit - Digits
Minlen defines "credits" not length
1 credit for each character
Additional credits for other criteria
Use a -1 to indicate one or more of a character
Does not count for credits
Example: minlen=8 lcredit=1 ucredit=1 ocredit=1 dcredit=1
Password: 12345678
Passes
One credit for each character (+8)
One credit for each number (dcredit) (+8)
Adds up to 16 credits
Example: minlen=8 lcredit=1 ucredit=-1 ocredit=-1 dcredit=-1
Password: 12345678
Fails
One credit for each character (+8)
Penalty for missing an upper case character (-1)
Penalty for missing a lower case character (-1)
Penalty for missing a special character (-1)
Adds up to 5
Password: P@ssw0rd
One credit for each character (+8)
No penalty for missing an upper case character (+0)
No penalty for missing a lower case character (+0)
No penalty for missing a special character (+0)
Adds up to 8