STIGUI
V-282465CAT II — Medium severitySV-282465r1262393_rule

TOSS 5 user account passwords for new users or password changes must have a 180-day maximum password lifetime restriction in /etc/login.defs.

Rule version TOSS-05-000291 · STIG v1 · 2026-08-20

Discussion

Any password, no matter how complex, can eventually be cracked; therefore, passwords must be changed periodically. If the operating system does not limit the lifetime of passwords and force users to change their passwords, there is the risk that the operating system passwords could be compromised.

Setting the password maximum age ensures users are required to periodically change their passwords. Requiring shorter password lifetimes increases the risk of users writing down the password in a convenient location subject to physical compromise.

Check

Verify TOSS 5 enforces a 180-day maximum password lifetime for new user accounts using the following command:

$ grep -i pass_max_days /etc/login.defs

PASS_MAX_DAYS 180

If the "PASS_MAX_DAYS" parameter value is greater than "180" or commented out, this is a finding.

Fix

Configure TOSS 5 to enforce a 180-day maximum password lifetime.

Add or modify the following line in the "/etc/login.defs" file:

PASS_MAX_DAYS 180

Identifiers

Group ID
V-282465
Group title
SRG-OS-000076-GPOS-00044
Rule ID
SV-282465r1262393_rule
Check ID
C-87026r1262391_chk
Fix ID
F-86931r1262392_fix