SRG-OS-000073-GPOS-00041 Controls

STIG IDVersionTitleProduct
ALMA-09-037200V1R1AlmaLinux OS 9 PAM must be configured to use a sufficient number of password hashing rounds.
ALMA-09-037310V1R1AlmaLinux OS 9 must be configured so that libuser is configured to store only encrypted representations of passwords.
ALMA-09-037420V1R1AlmaLinux OS 9 must be configured so that the system's shadow file is configured to store only encrypted representations of passwords.
ALMA-09-037530V1R1AlmaLinux OS 9 must be configured so that the Pluggable Authentication Module is configured to store only encrypted representations of passwords.
ALMA-09-037640V1R1AlmaLinux OS 9 must be configured so that interactive user account passwords are using strong password hashes.
UBTU-18-010104V2R15The Ubuntu operating system must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm.
UBTU-24-400220V1R1Ubuntu 24.04 LTS must store only encrypted representations of passwords.
WN22-AC-000090V2R1Windows Server 2022 reversible password encryption must be disabled.
WN22-SO-000300V2R1Windows Server 2022 must be configured to prevent the storage of the LAN Manager hash of passwords.
WN10-AC-000045V2R8Reversible password encryption must be disabled.
WN10-SO-000195V2R8The system must be configured to prevent the storage of the LAN Manager hash of passwords.
WN11-AC-000045V2R1Reversible password encryption must be disabled.
WN11-SO-000195V2R1The system must be configured to prevent the storage of the LAN Manager hash of passwords.
UBTU-22-611055V2R1Ubuntu 22.04 LTS must store only encrypted representations of passwords.
RHEL-08-010110V1R9RHEL 8 must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm.
RHEL-08-010120V1R9RHEL 8 must employ FIPS 140-2 approved cryptographic hashing algorithms for all stored passwords.
RHEL-08-010130V1R9The RHEL 8 shadow password suite must be configured to use a sufficient number of hashing rounds.
RHEL-07-010200V3R8The Red Hat Enterprise Linux operating system must be configured so that the PAM system service is configured to store only encrypted representations of passwords.
RHEL-07-010210V3R8The Red Hat Enterprise Linux operating system must be configured to use the shadow file to store only encrypted representations of passwords.
RHEL-07-010220V3R8The Red Hat Enterprise Linux operating system must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords.
RHEL-09-611050V2R1RHEL 9 password-auth must be configured to use a sufficient number of hashing rounds.
RHEL-09-611055V2R1RHEL 9 system-auth must be configured to use a sufficient number of hashing rounds.
RHEL-09-611135V2R1RHEL 9 must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords.
RHEL-09-611140V2R1RHEL 9 must be configured to use the shadow file to store only encrypted representations of passwords.
RHEL-09-611150V2R1RHEL 9 shadow password suite must be configured to use a sufficient number of hashing rounds.
RHEL-09-671015V2R1RHEL 9 must employ FIPS 140-3 approved cryptographic hashing algorithms for all stored passwords.
RHEL-09-671025V2R1RHEL 9 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-3 approved cryptographic hashing algorithm for system authentication.
OL09-00-001050V1R1OL 9 must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords.
OL09-00-001055V1R1OL 9 must be configured to use the shadow file to store only encrypted representations of passwords.
OL09-00-001060V1R1OL 9 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-3 approved cryptographic hashing algorithm for system authentication.
OL09-00-001065V1R1OL 9 password-auth must be configured to use a sufficient number of hashing rounds.
OL09-00-001070V1R1OL 9 system-auth must be configured to use a sufficient number of hashing rounds.
OL09-00-001075V1R1OL 9 shadow password suite must be configured to use a sufficient number of hashing rounds.
OL09-00-001080V1R1OL 9 must employ FIPS 140-3 approved cryptographic hashing algorithms for all stored passwords.
WN16-AC-000090V2R10Windows Server 2016 reversible password encryption must be disabled.
WN16-SO-000360V2R10Windows Server 2016 must be configured to prevent the storage of the LAN Manager hash of passwords.
SLES-15-020170V1R9The SUSE operating system must configure the Linux Pluggable Authentication Modules (PAM) to only store encrypted representations of passwords.
SLES-15-020180V1R9The SUSE operating system must employ FIPS 140-2-approved cryptographic hashing algorithms for all stored passwords.
SLES-15-020190V1R9The SUSE operating system must employ FIPS 140-2-approved cryptographic hashing algorithms for all stored passwords.
SLES-12-010220V2R13The SUSE operating system must employ FIPS 140-2-approved cryptographic hashing algorithms for all stored passwords.
SLES-12-010230V2R13The SUSE operating system must configure the Linux Pluggable Authentication Modules (PAM) to only store encrypted representations of passwords.
SLES-12-010240V2R13The SUSE operating system must employ FIPS 140-2-approved cryptographic hashing algorithms for all stored passwords.
OL07-00-010200V2R14The Oracle Linux operating system must be configured so that the PAM system service is configured to store only encrypted representations of passwords.
OL07-00-010210V2R14The Oracle Linux operating system must be configured to use the shadow file to store only encrypted representations of passwords.
OL07-00-010220V2R14The Oracle Linux operating system must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords.
OL07-00-010199V2R14The Oracle Linux operating system must be configured to prevent overwriting of custom authentication configuration settings by the authconfig utility.
WN19-AC-000090V2R8Windows Server 2019 reversible password encryption must be disabled.
WN19-SO-000300V2R8Windows Server 2019 must be configured to prevent the storage of the LAN Manager hash of passwords.
OL08-00-010110V1R9OL 8 must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm.
OL08-00-010120V1R9OL 8 must employ FIPS 140-2 approved cryptographic hashing algorithms for all stored passwords.
OL08-00-010130V1R9The OL 8 shadow password suite must be configured to use a sufficient number of hashing rounds.