content icon indicating copy to clipboard operation
content copied to clipboard

5.5.1.4 Ensure inactive password lock is 30 days or less (Scored)

Open shawndwells opened this issue 5 years ago • 3 comments

shawndwells avatar Mar 29 '20 04:03 shawndwells

The INACTIVE setting is cheked by account_disable_post_pw_expiration. But actual list of users is not verified. I.E. if any user with passsword inactive for more than 30 days are inactive.

yuumasato avatar May 19 '20 21:05 yuumasato

@yuumasato good point. Seems like CIS should break that out into it's own rule, but anyway, reading the rule from the CIS benchmark itself, I thought chage -l user can show inactivity.

redhatrises avatar May 19 '20 22:05 redhatrises

~~I believe the check of existing userspasswords is covered by:~~ ~~-accounts_password_set_max_life_existing~~ ~~- accounts_password_set_min_life_existing`~~

~~I'll add them to CIS control files soon.~~

Edit: Actually, the rules I mention are about active interactive user, not inactive users.

yuumasato avatar Dec 15 '21 12:12 yuumasato