STIGUI
V-268134CAT II — Medium severitySV-268134r1131073_rule

NixOS must enforce a minimum 15-character password length.

Rule version ANIX-00-000810 · STIG v1 · 2025-08-19

Discussion

The shorter the password, the lower the number of possible combinations that need to be tested before the password is compromised.

Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. Password length is one factor of several that helps to determine strength and how long it takes to crack a password. Use of more characters in a password helps to exponentially increase the time and/or resources required to compromise the password.

Check

Verify NixOS enforces a minimum 15-character password length with the following command:

$ grep minlen /etc/security/pwquality.conf

minlen=15

If the value of "minlen" is set to less than "15", or is commented out, this is a finding.

Fix

Configure NixOS to enforce password complexity.

Add the following Nix code to the NixOS Configuration, usually located in /etc/nixos/configuration.nix or /etc/nixos/flake.nix:

environment.etc."/security/pwquality.conf".text = '' minlen=15 '';

Rebuild and switch to the new NixOS configuration: $ sudo nixos-rebuild switch

Identifiers

Group ID
V-268134
Group title
SRG-OS-000078-GPOS-00046
Rule ID
SV-268134r1131073_rule
Check ID
C-72058r1039288_chk
Fix ID
F-71961r1131072_fix