LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 07-27-2015, 11:18 AM   #1
bluephoric
LQ Newbie
 
Registered: Jul 2015
Posts: 3

Rep: Reputation: Disabled
CentOS password parameters for pci compliance


Hello, I am new to Linux and need some help with setting password paramenters. Below is a list of tasks I need to accomplish. Is there one file I can edit for this? Maybe a good article with a walkthrough? Any help would be greatly appreciated.
All our servers run CentOS.
• Invalid attempts – not set to lock out after 6 invalid attempts
• Lockout duration – not set to at least 30 minutes or until an administrator enables the user ID.
• Minimum password length – set to 5; needs to be set to at least 7. Complexity has not been set.
• Password Age – not set. Needs to be at least once every 90 days.
• Password History – not set. Needs to be set so that a new password/phrase cannot be the same as, at least, the last four passwords/phrases.
 
Old 07-27-2015, 12:33 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by bluephoric View Post
Hello, I am new to Linux and need some help with setting password paramenters.
If you're new to Linux did you start reading this distributions user, admin and security documentation? Because if you didn't that would be very inefficient. Please see https://access.redhat.com/documentat...erprise_Linux/ and http://wiki.centos.org/Documentation


Quote:
Originally Posted by bluephoric View Post
All our servers run CentOS.
Do these by any chance include any "inherited" ones? ;-p


'cd /usr/share/doc/pam-*/txts || exit 1;'
'ls -al /etc/pam.d;'
Quote:
Originally Posted by bluephoric View Post
Invalid attempts – not set to lock out after 6 invalid attempts
README.pam_tally* ?

Quote:
Originally Posted by bluephoric View Post
Lockout duration – not set to at least 30 minutes or until an administrator enables the user ID.
README.pam_faillock?

Quote:
Originally Posted by bluephoric View Post
Minimum password length – set to 5; needs to be set to at least 7. Complexity has not been set.
README.pam_unix, README.pam_cracklib and 'man pam_passwdqc'?

Quote:
Originally Posted by bluephoric View Post
Password Age – not set. Needs to be at least once every 90 days.
'man chage'?

Quote:
Originally Posted by bluephoric View Post
Password History – not set.
README.pam_unix and or README.pam_pwhistory?
 
1 members found this post helpful.
Old 07-30-2015, 03:22 PM   #3
bluephoric
LQ Newbie
 
Registered: Jul 2015
Posts: 3

Original Poster
Rep: Reputation: Disabled
I think we have the password policy working but now have run into the issue of exemptions. We have certain accounts we do not want to require changing. I am still looking but if someone may have had experience with this and could offer some insight it would be greatly appreciated.
 
  


Reply

Tags
centos, passwords



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Update Apache in CentOS 5.8 for PCI Compliance hruday Linux - Newbie 1 06-23-2015 07:46 PM
PCI Compliance fetal Linux - Server 6 02-11-2013 09:55 PM
is PCI Compliance possible in a multi-node cloud setup? sneakyimp Linux - Security 2 10-11-2012 07:39 PM
vsftpd and PCI compliance saraza Linux - Networking 3 09-22-2012 01:39 PM
apache 2.2.3 / RHEL 5 / PCI Compliance / openssl sowell Linux - Server 2 12-09-2009 09:26 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 02:30 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration