Password policies
Having your own password policy protects the system from the use of weak passwords. Determine the length and complexity of the user passwords used and follow the recommendations below:
To define a password policy, edit the file /etc/pam.d/passwd as follows:
sudo nano /etc/pam.d/passwdDepending on your needs, add an entry for the pam_passwdqc module or modify an existing entry accordingly. One possible configuration, for example, is:
password requisite pam_passwdqc.so min=disabled,disabled,disabled,disabled,10 similar=deny retry=3 en-force=users@include common passwordIf an entry for pam_passwdqc is already present, update it; do not add a second entry. Existing PAM lines related to actual password processing must not be removed.
For the parameter pam_passwdqc.so, at least five values can be set. These five values represent predefined password categories. Each position can either be disabled using “disabled” or assigned a number representing the required minimum length. The positions represent the following password categories:
- Passwords consisting of a single character set–that is, passwords consisting only of numbers or only of lowercase or uppercase letters;
- Passwords consisting of two character classes are allowed, i.e. passwords that consist of lowercase and uppercase letters, for example;
- Passphrases are allowed, i.e. strings of characters that can be separated by spaces;
- Passwords consisting of three character classes, such as lowercase and uppercase letters and numbers;
- Passwords consisting of four character classes: lowercase and uppercase letters, numbers, and special characters.
The example shown therefore only allows passwords that consist of all four character classes and are at least 10 characters long.
The similar=deny parameter specifies that the new password must not be similar to the previous one. The retry=3 parameter determines how often a user is prompted to enter a new password if the chosen password does not meet the requirements of the password policy. With enforce=users, the user account policy is enforced.