ansible-hardening/doc/metadata/rhel7/RHEL-07-010110.rst
Major Hayden 29cbeb50a8 [Docs] Apply password quality rules
This patch adds documentation for:

  https://review.openstack.org/399174

Implements: blueprint security-rhel7-stig
Change-Id: I9062c95f2dd4f91e2ff44dcefde99fde013fca9d
2016-11-29 19:23:05 +00:00

30 lines
947 B
ReStructuredText

---
id: RHEL-07-010110
status: opt-in
tag: auth
---
The password quality requirements from the STIG are examples of good security
practice, but deployers are strongly encouraged to use centralized
authentication for administrative server access whenever possible.
Password quality requirements are controlled by two Ansible variables: one for
each individual password requirement and one "master switch" variable. The
master switch variable controls all password requirements and it is **disabled
by default**.
Deployers can enable all password quality requirements by setting the master
switch variable to ``yes``:
.. code-block:: yaml
security_pwquality_apply_rules: yes
When the master switch variable is enabled, each individual password quality
requirement can be disabled by a variable. To disable the fix for this STIG
control, set the following Ansible variable:
.. code-block:: yaml
security_pwquality_require_numeric: no