The system must require passwords to contain at least one numeric character.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-216329SOL-11.1-040090SV-216329r1016274_ruleCCI-004066medium
Description
Complex passwords can reduce the likelihood of success of automated password-guessing attacks.
STIGDate
Solaris 11 SPARC Security Technical Implementation Guide2025-05-05

Details

Check Text (C-216329r1016274_chk)

Check the MINDIGIT setting. # grep ^MINDIGIT /etc/default/passwd If the MINDIGIT setting is less than 1, this is a finding.

Fix Text (F-17563r371076_fix)

The root role is required. # pfedit /etc/default/passwd Locate the line containing: MINDIGIT Change the line to read: MINDIGIT=1