DISA STIGS Viewer

NixOS must require the change of at least 50 percent of the total number of characters when passwords are changed.

Overview

Finding ID Version Rule ID IA Controls Severity
V-268129 ANIX-00-000760 SV-268129r1039275_rule   Medium
Description
Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks.
STIG Date
Anduril NixOS Security Technical Implementation Guide 2024-10-25

Details

Check Text (C-72053r1039273_chk)
Verify NixOS enforces password complexity by requiring that at least 50 percent of the characters are changed with the following command:

$ grep difok /etc/security/pwquality.conf

difok=8

If the value of "difok" is set to less than "8", or is commented out, this is a finding.
Fix Text (F-71956r1039274_fix)
Configure NixOS to enforce password complexity.

Add/modify /etc/nixos/configuration.nix to include the following lines:

environment.etc."/security/pwquality.conf".text = ''
difok=8
'';

Rebuild the system with the following command:

$ sudo nixos-rebuild switch