Password policies

Having your own password policy protects the system from the use of weak passwords. Determine the length and complexity of the user passwords used and follow the recommendations below:

To define a password policy, edit the file /etc/pam.d/passwd as follows:

sudo nano /etc/pam.d/passwd

Depending on your needs, add an entry for the pam_passwdqc module or modify an existing entry accordingly. One possible configuration, for example, is:

password    requisite    pam_passwdqc.so min=disabled,disabled,disabled,disabled,10 similar=deny retry=3 en-force=users
@include common password

If an entry for pam_passwdqc is already present, update it; do not add a second entry. Existing PAM lines related to actual password processing must not be removed.

For the parameter pam_passwdqc.so, at least five values can be set. These five values represent predefined password categories. Each position can either be disabled using “disabled” or assigned a number representing the required minimum length. The positions represent the following password categories:

The example shown therefore only allows passwords that consist of all four character classes and are at least 10 characters long.

The similar=deny parameter specifies that the new password must not be similar to the previous one. The retry=3 parameter determines how often a user is prompted to enter a new password if the chosen password does not meet the requirements of the password policy. With enforce=users, the user account policy is enforced.