Archives

Archive for Junio, 2009

Enforcing password policy on linux systems

( +techno )

Password expiration:

Debian/Ubuntu/Red Hat
edit /etc/login.defs

PASS_MAX_DAYS 90
PASS_MIN_DAYS 0
PASS_MIN_LEN 8
PASS_WARN_AGE 7

Password History:

Debian/Ubuntu/Red Hat
Create the password history file and secure it:

sudo touch /etc/security/opasswd
sudo chown root:root /etc/security/opasswd
sudo chmod 600 /etc/security/opasswd

Debian/Ubuntu
edit /etc/pam.d/common-password
comment out

password requisite pam_unix.so nullok obscure md5

and uncomment

password required […]