5.4.1.3 Ensure password expiration warning days is configured
Audit#
Run the following command and verify PASS_WARN_AGE is 7 or more and follows local site policy:
Example output:
Run the following command to verify all passwords have a PASS_WARN_AGE of 7 or more:
Nothing should be returnedRemediation#
Edit /etc/login.defs and set PASS_WARN_AGE to a value of 7 or more that follows local site policy: Example:
Run the following command to modify user parameters for all users with a password set to a minimum warning to 7 or more days that follows local site policy:
Example:
Default Value: PASS_WARN_AGE 7