The system must require passwords to contain at least one special character.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-216095SRG-OS-000266SOL-11.1-040100SV-216095r1016290_rule2024-11-253
Description
Complex passwords can reduce the likelihood of success of automated password-guessing attacks.
ℹ️ Check
Check the MINSPECIAL setting. # grep ^MINSPECIAL /etc/default/passwd If the MINSPECIAL setting is less than one, this is a finding.
✔️ Fix
The root role is required. # pfedit /etc/default/passwd a Locate the line containing: MINSPECIAL Change the line to read: MINSPECIAL=1