data:image/s3,"s3://crabby-images/4fa2d/4fa2dc578cb9f460ca6d8114d888f856144ad8ce" alt="Major Hayden"
This patch adds documentation for: https://review.openstack.org/399174 Implements: blueprint security-rhel7-stig Change-Id: I9062c95f2dd4f91e2ff44dcefde99fde013fca9d
947 B
---id: RHEL-07-010110 status: opt-in tag: auth ---
The password quality requirements from the STIG are examples of good security practice, but deployers are strongly encouraged to use centralized authentication for administrative server access whenever possible.
Password quality requirements are controlled by two Ansible variables: one for each individual password requirement and one "master switch" variable. The master switch variable controls all password requirements and it is disabled by default.
Deployers can enable all password quality requirements by setting the
master switch variable to yes
:
security_pwquality_apply_rules: yes
When the master switch variable is enabled, each individual password quality requirement can be disabled by a variable. To disable the fix for this STIG control, set the following Ansible variable:
security_pwquality_require_numeric: no