The operating system must enforce password complexity requiring that at least one lowercase character is used.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-216093SOL-11.1-040080SV-216093r1016288_ruleCCI-004066medium
Description
Complex passwords can reduce the likelihood of success of automated password-guessing attacks.
STIGDate
Solaris 11 X86 Security Technical Implementation Guide2025-05-05

Details

Check Text (C-216093r1016288_chk)

Check the MINLOWER setting. # grep ^MINLOWER /etc/default/passwd If MINLOWER is not set to one or more, this is a finding.

Fix Text (F-17329r986436_fix)

The root role is required. # pfedit /etc/default/passwd Locate the line containing: MINLOWER Change the line to read: MINLOWER=1