Rule version ANIX-00-001860 · STIG v1 · 2025-08-19
If the operating system allows the user to select passwords based on dictionary words, then this increases the chances of password compromise by increasing the opportunity for successful guesses and brute-force attacks.
Verify NixOS prevents the use of dictionary words for passwords with the following command:
$ grep dictcheck /etc/security/pwquality.conf
dictcheck=1
If the value of "ocredit" is a positive number or is commented out, this is a finding.
Configure NixOS to check password change attempts against a dictionary.
Add the following Nix code to the NixOS Configuration, usually located in /etc/nixos/configuration.nix or /etc/nixos/flake.nix:
environment.etc."/security/pwquality.conf".text = '' dictcheck=1 '';
Rebuild and switch to the new NixOS configuration: $ sudo nixos-rebuild switch