Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-1482

Incorrect PAM configuration after remediation

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • No
    • None
    • rhel-security-compliance
    • ssg_security
    • 1
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • None
    • None
    • Release Note Not Required
    • None
    • 57,005

      Description of problem:
      When applying CIS Level 2 - Server security profile during RHEL 9.1 installation the password encryption algorithm is configured twice and it's unclear which one would be used:

      password sufficient pam_unix.so yescrypt shadow use_authtok sha512

      This should obviously read (when sha512 is wanted):

      password sufficient pam_unix.so sha512 shadow use_authtok

      Version-Release number of selected component (if applicable):
      RHEL 9.1

              maburgha@redhat.com Marcus Burghardt
              myllynen Marko Myllynen
              Vojtech Polasek
              Marcus Burghardt Marcus Burghardt
              SSG Security QE SSG Security QE
              Votes:
              0 Vote for this issue
              Watchers:
              11 Start watching this issue

                Created:
                Updated:
                Resolved: