| name | cis-ubuntu2004-v300-5-3-3-3-3 |
| description | Ensure pam_pwhistory includes use_authtok |
| category | cis-iam |
| version | 3.0.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-20.04","pam","authentication"] |
| cis_id | 5.3.3.3.3 |
| cis_benchmark | CIS Ubuntu Linux 20.04 LTS Benchmark v3.0.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
5.3.3.3.3 Ensure pam_pwhistory includes use_authtok (Automated)
Profile Applicability
- Level 1 - Server
- Level 1 - Workstation
Description
use_authtok - When password changing enforce the module to set the new password to the one provided by a previously stacked password module.
Rationale
use_authtok allows multiple pam modules to confirm a new password before it is accepted.
Audit Procedure
Command Line
Run the following command to verify that the use_authtok argument exists on the pwhistory line in /etc/pam.d/common-password:
Expected Result
Output should be similar to:
password requisite pam_pwhistory.so remember=24 enforce_for_root use_authtok
Remediation
Command Line
Run the following command:
Edit any returned files and add the use_authtok argument to the pam_pwhistory line in the Password section:
Example File:
Name: pwhistory password history checking
Default: yes
Priority: 1024
Password-Type: Primary
Password:
requisite pam_pwhistory.so remember=24 enforce_for_root use_authtok # <- **ensure line includes use_authtok**
Run the following command to update the files in the /etc/pam.d/ directory:
Example:
References
- NIST SP 800-53 Rev. 5: IA-5
CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|
|