The operating system must not allow logins for users with blank passwords.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-216128SOL-11.1-040480SV-216128r959010_ruleCCI-000366high
Description
If the password field is blank and the system does not enforce a policy that passwords are required, it could allow login without proper authentication of a user.
STIGDate
Solaris 11 X86 Security Technical Implementation Guide2025-05-05

Details

Check Text (C-216128r959010_chk)

Determine if the system is enforcing a policy that passwords are required. # grep ^PASSREQ /etc/default/login If the command does not return: PASSREQ=YES this is a finding.

Fix Text (F-17364r372767_fix)

The root role is required. Modify the /etc/default/login file. # pfedit /etc/default/login Insert the line: PASSREQ=YES