LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 10-18-2012, 09:50 AM   #1
etcetera
Member
 
Registered: Aug 2004
Posts: 436

Rep: Reputation: 17
Setting password security policy


I need the following password security policy, which files do I modify other than /etc/pam.d/system-auth
Or is there a quick command to do all this? Needs to apply to all accounts on the system.

Administrator passwords must be at 8 chars.
And must include at least 1 upper case, 1 lower case, 1 number and 1 special character.

· Difference: must change at least 2 characters.

· Password Age of not greater than 180 days
.
· Password Age of not less than 24 hours.

· Passwords must not be reused for 10 generations.
 
Old 10-18-2012, 11:29 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by etcetera View Post
which files do I modify other than /etc/pam.d/system-auth
/etc/security/opasswd if you don't have it and aging parms are taken from /etc/login.defs.


Quote:
Originally Posted by etcetera View Post
Needs to apply to all accounts on the system.
Note you can chage accounts pro-actively but password strength policy changes are only enforced on next password change.
 
Old 10-18-2012, 11:37 AM   #3
etcetera
Member
 
Registered: Aug 2004
Posts: 436

Original Poster
Rep: Reputation: 17
I have the file /etc/security/opasswd but it's zero in size.
 
Old 10-18-2012, 01:26 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Like I said password strength policy changes are only enforced on next password change. So if it's empty it hasn't been used yet.
 
Old 10-18-2012, 03:29 PM   #5
etcetera
Member
 
Registered: Aug 2004
Posts: 436

Original Poster
Rep: Reputation: 17
what about /etc/login.defs
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Configure my Redhat directory server password policy and account lockout policy arunplanet Linux - Newbie 4 10-06-2012 08:59 AM
How will you implement account lockout policy in linux? sulekha Ubuntu 3 02-10-2012 07:33 PM
Account Lockout Policy in Linux? wardialer Linux - Security 15 02-19-2009 09:38 AM
OpenLDAP account policy Goretex Linux - Security 1 07-18-2007 11:51 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 02:21 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration