Details
-
Bug
-
Resolution: Unresolved
-
Undefined
-
None
-
rhel-9.1.0
-
Assignee, Qa Contact, Doc Contact, Pool Team, Watchers, Developer
-
sst_security_compliance
-
ssg_security
-
False
-
-
Unspecified
-
No Doc Update
-
Unspecified
Description
Description of problem:
When applying CIS Level 2 - Server security profile during RHEL 9.1 installation the password encryption algorithm is configured twice and it's unclear which one would be used:
password sufficient pam_unix.so yescrypt shadow use_authtok sha512
This should obviously read (when sha512 is wanted):
password sufficient pam_unix.so sha512 shadow use_authtok
Version-Release number of selected component (if applicable):
RHEL 9.1
Attachments
Issue Links
- external trackers