IA-5 Authenticator Management
Identification and Authentication family. 101 Control Correlation Identifiers map to this control, and 113 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to IA-5 |
|---|---|---|
| Red Hat Enterprise Linux 9 | V2 | 27 |
| Red Hat Enterprise Linux 8 | V2 | 21 |
| Microsoft Windows Server 2019 | V3 | 18 |
| Microsoft Windows Server 2022 | V2 | 18 |
| Microsoft Windows 10 | V3 | 14 |
| Microsoft Windows 11 | V2 | 12 |
| Kubernetes | V2 | 2 |
| Google Chrome Current Windows | V2 | 1 |
Control Correlation Identifiers mapped to IA-5
| CCI | Definition | Rev |
|---|---|---|
| CCI-000176 | Manage system authenticators by establishing initial authenticator content for authenticators issued by the organization. | 5, 4 |
| CCI-000179 | The organization manages information system authenticators by establishing minimum lifetime restrictions for authenticators. | 4 |
| CCI-000180 | The organization manages information system authenticators by establishing maximum lifetime restrictions for authenticators. | 4 |
| CCI-000181 | The organization manages information system authenticators by establishing reuse conditions for authenticators. | 4 |
| CCI-000182 | Manage system authenticators by changing or refreshing authenticators in accordance with the organization-defined time period by authenticator type or when organization-defined events occur. | 5, 4 |
| CCI-000183 | Manage system authenticators by protecting authenticator content from unauthorized disclosure. | 5, 4 |
| CCI-000184 | Manage system authenticators by requiring individuals to take, and having devices implement, specific security controls to protect authenticators. | 5, 4 |
| CCI-000185 | For public key-based authentication, validate certificates by constructing and verifying a certification path to an accepted trust anchor including checking certificate status information. | 5, 4 |
| CCI-000186 | For public key-based authentication, enforce authorized access to the corresponding private key. | 5, 4 |
| CCI-000187 | For public key-based authentication, map the authenticated identity to the account of the individual or group. | 5, 4 |
| CCI-000192 | The information system enforces password complexity by the minimum number of upper case characters used. | 4 |
| CCI-000193 | The information system enforces password complexity by the minimum number of lower case characters used. | 4 |
| CCI-000194 | The information system enforces password complexity by the minimum number of numeric characters used. | 4 |
| CCI-000195 | The information system, for password-based authentication, when new passwords are created, enforces that at least an organization-defined number of characters are changed. | 4 |
| CCI-000196 | The information system, for password-based authentication, stores only cryptographically-protected passwords. | 4 |
| CCI-000197 | For password-based authentication, transmit passwords only over cryptographically-protected channels. | 5, 4 |
| CCI-000198 | The information system enforces minimum password lifetime restrictions. | 4 |
| CCI-000199 | The information system enforces maximum password lifetime restrictions. | 4 |
| CCI-000200 | The information system prohibits password reuse for the organization-defined number of generations. | 4 |
| CCI-000201 | Protect authenticators commensurate with the security category of the information to which use of the authenticator permits access. | 5, 4 |
| CCI-000202 | The organization ensures unencrypted static authenticators are not embedded in access scripts. | 4 |
| CCI-000203 | The organization ensures unencrypted static authenticators are not stored on function keys. | 4 |
| CCI-000204 | Defines the security controls required to manage the risk of compromise due to individuals having accounts on multiple systems. | 5, 4 |
| CCI-000205 | The information system enforces minimum password length. | 4 |
| CCI-001544 | Manage system authenticators by ensuring that authenticators have sufficient strength of mechanism for their intended use. | 5, 4 |
| CCI-001610 | Defines the time-period (by authenticator type) for changing/refreshing authenticators. | 5, 4 |
| CCI-001611 | The organization defines the minimum number of special characters for password complexity enforcement. | 4 |
| CCI-001612 | The organization defines the minimum number of upper case characters for password complexity enforcement. | 4 |
| CCI-001613 | The organization defines the minimum number of lower case characters for password complexity enforcement. | 4 |
| CCI-001614 | The organization defines the minimum number of numeric characters for password complexity enforcement. | 4 |
| CCI-001615 | The organization defines the minimum number of characters that are changed when new passwords are created. | 4 |
| CCI-001616 | The organization defines minimum password lifetime restrictions. | 4 |
| CCI-001617 | The organization defines maximum password lifetime restrictions. | 4 |
| CCI-001618 | The organization defines the number of generations for which password reuse is prohibited. | 4 |
| CCI-001619 | The information system enforces password complexity by the minimum number of special characters used. | 4 |
| CCI-001621 | Implement organization-defined security controls to manage the risk of compromise due to individuals having accounts on multiple systems. | 5, 4 |
| CCI-001980 | Manage system authenticators by verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, or device receiving the authenticator. | 5, 4 |
| CCI-001981 | Manage system authenticators by establishing administrative procedures for initial authenticator distribution. | 5, 4 |
| CCI-001982 | The organization manages information system authenticators by establishing administrative procedures for lost/compromised authenticators. | 4 |
| CCI-001983 | The organization manages information system authenticators by establishing administrative procedures for damaged authenticators. | 4 |
| CCI-001984 | Manage system authenticators by establishing administrative procedures for revoking authenticators. | 5, 4 |
| CCI-001985 | Manage system authenticators by implementing administrative procedures for initial authenticator distribution. | 5, 4 |
| CCI-001986 | The organization manages information system authenticators by implementing administrative procedures for lost/compromised authenticators. | 4 |
| CCI-001987 | The organization manages information system authenticators by implementing administrative procedures for damaged authenticators. | 4 |
| CCI-001988 | Manage system authenticators by implementing administrative procedures for revoking authenticators. | 5, 4 |
| CCI-001989 | The organization manages information system authenticators by changing default content of authenticators prior to information system installation. | 4 |
| CCI-001990 | Manage system authenticators by changing authenticators for group or role accounts when membership to those accounts changes. | 5, 4 |
| CCI-001991 | The information system, for PKI-based authentication, implements a local cache of revocation data to support path discovery and validation in case of inability to access revocation information via the network. | 4 |
| CCI-001992 | The organization defines the personnel or roles responsible for authorizing the organization's registration authority accountable for the authenticator registration process. | 4 |
| CCI-001993 | The organization defines the registration authority accountable for the authenticator registration process. | 4 |
| CCI-001994 | The organization defines the types of and/or specific authenticators that are subject to the authenticator registration process. | 4 |
| CCI-001995 | The organization requires that the registration process, to receive organization-defined types of and/or specific authenticators, be conducted in person, or by a trusted third-party, before an organization-defined registration authority with authorization by organization-defined personnel or roles. | 4 |
| CCI-001996 | The organization defines the requirements required by the automated tools to determine if password authenticators are sufficiently strong. | 4 |
| CCI-001997 | The organization employs automated tools to determine if password authenticators are sufficiently strong to satisfy organization-defined requirements. | 4 |
| CCI-001998 | Require developers and installers of system components to provide unique authenticators or change default authenticators prior to delivery and installation. | 5, 4 |
| CCI-001999 | The organization defines the external organizations to be coordinated with for cross-organization management of credentials. | 4 |
| CCI-002000 | The organization coordinates with organization-defined external organizations for cross-organization management of credentials. | 4 |
| CCI-002001 | Bind identities and authenticators dynamically using organization-defined binding rules. | 5, 4 |
| CCI-002002 | The organization defines the token quality requirements to be employed by the information system mechanisms for token-based authentication. | 4 |
| CCI-002003 | The information system, for token-based authentication, employs mechanisms that satisfy organization-defined token quality requirements. | 4 |
| CCI-002004 | Defines the biometric quality requirements to be employed by the mechanisms for biometric-based authentication. | 5, 4 |
| CCI-002005 | For biometric-based authentication, employ mechanisms that satisfy organization-defined biometric quality requirements. | 5, 4 |
| CCI-002006 | Defines the time period after which the use of cached authenticators is prohibited. | 5, 4 |
| CCI-002007 | Prohibit the use of cached authenticators after an organization-defined time period. | 5, 4 |
| CCI-002008 | For PKI-based authentication, employs an organization-wide methodology for managing the content of PKI trust stores installed across all platforms including networks, operating systems, browsers, and applications. | 5, 4 |
| CCI-002041 | The information system allows the use of a temporary password for system logons with an immediate change to a permanent password. | 4 |
| CCI-002042 | Manage system authenticators by protecting authenticator content from unauthorized modification. | 5, 4 |
| CCI-002043 | The organization uses only FICAM-approved path discovery and validation products and services. | 4 |
| CCI-002365 | The organization manages information system authenticators by requiring individuals to take specific security safeguards to protect authenticators. | 4 |
| CCI-002366 | The organization manages information system authenticators by having devices implement specific security safeguards to protect authenticators. | 4 |
| CCI-002367 | The organization ensures unencrypted static authenticators are not embedded in applications. | 4 |
| CCI-004053 | Manage system authenticators by establishing administrative procedures for lost/compromised or damaged authenticators. | 5 |
| CCI-004054 | Manage system authenticators by implementing administrative procedures for lost/compromised or damaged authenticators. | 5 |
| CCI-004055 | Manage system authenticators by changing default authenticators prior to first use. | 5 |
| CCI-004056 | Defines the events for when to change or refresh authenticators. | 5 |
| CCI-004057 | Defines the frequency for updating commonly used, expected, or compromised passwords, when they are suspected of being compromised directly or indirectly. | 5 |
| CCI-004058 | For password-based authentication, maintain a list of commonly used, expected, or compromised passwords on an organization-defined frequency. | 5 |
| CCI-004059 | For password-based authentication, update the list of passwords on an organization-defined frequency. | 5 |
| CCI-004060 | For password-based authentication, update the list of passwords when organizational passwords are suspected to have been compromised directly or indirectly. | 5 |
| CCI-004061 | For password-based authentication, verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a). | 5 |
| CCI-004062 | For password-based authentication, store passwords using an approved salted key derivation function, preferably using a keyed hash. | 5 |
| CCI-004063 | For password-based authentication, require immediate selection of a new password upon account recovery. | 5 |
| CCI-004064 | For password-based authentication, allow user selection of long passwords and passphrases, including spaces and all printable characters. | 5 |
| CCI-004065 | For password-based authentication, employ automated tools to assist the user in selecting strong password authenticators. | 5 |
| CCI-004066 | For password-based authentication, enforce organization-defined composition and complexity rules. | 5 |
| CCI-004067 | Defines the composition and complexity rules to be enforced. | 5 |
| CCI-004068 | For public key-based authentication, implement a local cache of revocation data to support path discovery and validation. | 5 |
| CCI-004069 | Ensure that the unencrypted static authenticators are not embedded in applications or other forms of static storage. | 5 |
| CCI-004070 | Use organization-defined external organizations to federate credentials. | 5 |
| CCI-004071 | Defines the external organizations used to federate credentials. | 5 |
| CCI-004072 | Defines the binding rules for binding identities and authenticators. | 5 |
| CCI-004073 | Use only General Services Administration-approved and validated products and services for identity, credential, and access management. | 5 |
| CCI-004074 | Require that the issuance of organization-defined types of and/or specific authenticators be conducted in person or by a trusted external party before the organization-defined registration authority with authorization by organization-defined personnel or roles. | 5 |
| CCI-004075 | Defines types of and/or specific authenticators to be conducted in person or by a trusted external party before the organization-defined registration authority. | 5 |
| CCI-004076 | Defines the registration authority who conducts the issuance of organization-defined types of and/or specific authenticators. | 5 |
| CCI-004077 | Defines the personnel or roles who authorize the issuance of organization-defined types of and/or specific authenticators. | 5 |
| CCI-004078 | Employ presentation attack detection mechanisms for biometric-based authentication. | 5 |
| CCI-004079 | Employ organization-defined password managers to generate and manage passwords. | 5 |
| CCI-004080 | Defines the password managers employed to generate and manage passwords. | 5 |
| CCI-004081 | Protect the passwords using organization-defined controls. | 5 |
| CCI-004082 | Defines the controls for protecting the passwords. | 5 |
STIG rules that implement IA-5
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205645 | WN19-DC-000280 | medium | Windows Server 2019 domain controllers must have a PKI server certificate. |
| V-205646 | WN19-DC-000290 | high | Windows Server 2019 domain Controller PKI certificates must be issued by the DoD PKI or an approved External Certificate Authority (ECA). |
| V-205647 | WN19-DC-000300 | high | Windows Server 2019 PKI certificates associated with user accounts must be issued by a DoD PKI or an approved External Certificate Authority (ECA). |
| V-205648 | WN19-PK-000010 | medium | Windows Server 2019 must have the DoD Root Certificate Authority (CA) certificates installed in the Trusted Root Store. |
| V-205649 | WN19-PK-000020 | medium | Windows Server 2019 must have the DoD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems. |
| V-205650 | WN19-PK-000030 | medium | Windows Server 2019 must have the US DoD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems. |
| V-205651 | WN19-SO-000350 | medium | Windows Server 2019 users must be required to enter a password to access private keys stored on the computer. |
| V-205652 | WN19-AC-000080 | medium | Windows Server 2019 must have the built-in Windows password complexity policy enabled. |
| V-205653 | WN19-AC-000090 | high | Windows Server 2019 reversible password encryption must be disabled. |
| V-205654 | WN19-SO-000300 | high | Windows Server 2019 must be configured to prevent the storage of the LAN Manager hash of passwords. |
| V-205655 | WN19-SO-000180 | medium | Windows Server 2019 unencrypted passwords must not be sent to third-party Server Message Block (SMB) servers. |
| V-205656 | WN19-AC-000060 | medium | Windows Server 2019 minimum password age must be configured to at least one day. |
| V-205657 | WN19-00-000020 | medium | Windows Server 2019 passwords for the built-in Administrator account must be changed at least every 60 days. |
| V-205658 | WN19-00-000210 | medium | Windows Server 2019 passwords must be configured to expire. |
| V-205659 | WN19-AC-000050 | medium | Windows Server 2019 maximum password age must be configured to 60 days or less. |
| V-205660 | WN19-AC-000040 | medium | Windows Server 2019 password history must be configured to 24 passwords remembered. |
| V-205661 | WN19-00-000050 | medium | Windows Server 2019 manually managed application account passwords must be at least 14 characters in length. |
| V-205662 | WN19-AC-000070 | medium | Windows Server 2019 minimum password length must be configured to 14 characters. |
| V-220716 | WN10-00-000090 | medium | Accounts must be configured to require password expiration. |
| V-220742 | WN10-AC-000020 | medium | The password history must be configured to 24 passwords remembered. |
| V-220743 | WN10-AC-000025 | medium | The maximum password age must be configured to 60 days or less. |
| V-220744 | WN10-AC-000030 | medium | The minimum password age must be configured to at least 1 day. |
| V-220745 | WN10-AC-000035 | medium | Passwords must, at a minimum, be 14 characters. |
| V-220746 | WN10-AC-000040 | medium | The built-in Microsoft password complexity filter must be enabled. |
| V-220747 | WN10-AC-000045 | high | Reversible password encryption must be disabled. |
| V-220903 | WN10-PK-000005 | medium | The DoD Root CA certificates must be installed in the Trusted Root Store. |
| V-220904 | WN10-PK-000010 | medium | The External Root CA certificates must be installed in the Trusted Root Store on unclassified systems. |
| V-220905 | WN10-PK-000015 | medium | The DoD Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems. |
| V-220906 | WN10-PK-000020 | medium | The US DOD CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems. |
| V-220926 | WN10-SO-000110 | medium | Unencrypted passwords must not be sent to third-party SMB Servers. |
| V-220937 | WN10-SO-000195 | high | The system must be configured to prevent the storage of the LAN Manager hash of passwords. |
| V-220952 | WN10-SO-000280 | medium | Passwords for enabled local Administrator accounts must be changed at least every 60 days. |
| V-221579 | DTBC-0037 | medium | Online revocation checks must be performed. |
| V-230229 | RHEL-08-010090 | medium | RHEL 8, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor. |
| V-230230 | RHEL-08-010100 | medium | RHEL 8, for certificate-based authentication, must enforce authorized access to the corresponding private key. |
| V-230231 | RHEL-08-010110 | medium | RHEL 8 must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm. |
| V-230232 | RHEL-08-010120 | medium | RHEL 8 must employ FIPS 140-2 approved cryptographic hashing algorithms for all stored passwords. |
| V-230233 | RHEL-08-010130 | medium | The RHEL 8 shadow password suite must be configured to use a sufficient number of hashing rounds. |
| V-230355 | RHEL-08-020090 | medium | RHEL 8 must map the authenticated identity to the user or group account for PKI-based authentication. |
| V-230357 | RHEL-08-020110 | medium | RHEL 8 must enforce password complexity by requiring that at least one uppercase character be used. |
| V-230358 | RHEL-08-020120 | medium | RHEL 8 must enforce password complexity by requiring that at least one lower-case character be used. |
| V-230359 | RHEL-08-020130 | medium | RHEL 8 must enforce password complexity by requiring that at least one numeric character be used. |
| V-230360 | RHEL-08-020140 | medium | RHEL 8 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed. |
| V-230361 | RHEL-08-020150 | medium | RHEL 8 must require the maximum number of repeating characters be limited to three when passwords are changed. |
| V-230362 | RHEL-08-020160 | medium | RHEL 8 must require the change of at least four character classes when passwords are changed. |
| V-230363 | RHEL-08-020170 | medium | RHEL 8 must require the change of at least 8 characters when passwords are changed. |
| V-230364 | RHEL-08-020180 | medium | RHEL 8 passwords must have a 24 hours/1 day minimum password lifetime restriction in /etc/shadow. |
| V-230365 | RHEL-08-020190 | medium | RHEL 8 passwords for new users or password changes must have a 24 hours/1 day minimum password lifetime restriction in /etc/login.defs. |
| V-230366 | RHEL-08-020200 | medium | RHEL 8 user account passwords must have a 60-day maximum password lifetime restriction. |
| V-230367 | RHEL-08-020210 | medium | RHEL 8 user account passwords must be configured so that existing passwords are restricted to a 60-day maximum lifetime. |
| V-230369 | RHEL-08-020230 | medium | RHEL 8 passwords must have a minimum of 15 characters. |
| V-230370 | RHEL-08-020231 | medium | RHEL 8 passwords for new users must have a minimum of 15 characters. |
| V-230375 | RHEL-08-020280 | medium | All RHEL 8 passwords must contain at least one special character. |
| V-230376 | RHEL-08-020290 | medium | RHEL 8 must prohibit the use of cached authentications after one day. |
| V-242415 | CNTR-K8-001160 | high | Secrets in Kubernetes must not be stored as environment variables. |
| V-253273 | WN11-00-000090 | medium | Accounts must be configured to require password expiration. |
| V-253300 | WN11-AC-000020 | medium | The password history must be configured to 24 passwords remembered. |
| V-253301 | WN11-AC-000025 | medium | The maximum password age must be configured to 60 days or less. |
| V-253302 | WN11-AC-000030 | medium | The minimum password age must be configured to at least 1 day. |
| V-253303 | WN11-AC-000035 | medium | Passwords must, at a minimum, be 14 characters. |
| V-253304 | WN11-AC-000040 | medium | The built-in Microsoft password complexity filter must be enabled. |
| V-253305 | WN11-AC-000045 | high | Reversible password encryption must be disabled. |
| V-253427 | WN11-PK-000005 | medium | The DoD Root CA certificates must be installed in the Trusted Root Store. |
| V-253428 | WN11-PK-000010 | medium | The External Root CA certificates must be installed in the Trusted Root Store on unclassified systems. |
| V-253450 | WN11-SO-000110 | medium | Unencrypted passwords must not be sent to third-party SMB Servers. |
| V-253461 | WN11-SO-000195 | high | The system must be configured to prevent the storage of the LAN Manager hash of passwords. |
| V-253476 | WN11-SO-000280 | medium | Passwords for enabled local Administrator accounts must be changed at least every 60 days. |
| V-254239 | WN22-00-000020 | medium | Windows Server 2022 passwords for the built-in Administrator account must be changed at least every 60 days. |
| V-254242 | WN22-00-000050 | medium | Windows Server 2022 manually managed application account passwords must be at least 14 characters in length. |
| V-254258 | WN22-00-000210 | medium | Windows Server 2022 passwords must be configured to expire. |
| V-254288 | WN22-AC-000040 | medium | Windows Server 2022 password history must be configured to 24 passwords remembered. |
| V-254289 | WN22-AC-000050 | medium | Windows Server 2022 maximum password age must be configured to 60 days or less. |
| V-254290 | WN22-AC-000060 | medium | Windows Server 2022 minimum password age must be configured to at least one day. |
| V-254291 | WN22-AC-000070 | medium | Windows Server 2022 minimum password length must be configured to 14 characters. |
| V-254292 | WN22-AC-000080 | medium | Windows Server 2022 must have the built-in Windows password complexity policy enabled. |
| V-254293 | WN22-AC-000090 | high | Windows Server 2022 reversible password encryption must be disabled. |
| V-254412 | WN22-DC-000280 | medium | Windows Server 2022 domain controllers must have a PKI server certificate. |
| V-254413 | WN22-DC-000290 | high | Windows Server 2022 domain Controller PKI certificates must be issued by the DoD PKI or an approved External Certificate Authority (ECA). |
| V-254414 | WN22-DC-000300 | high | Windows Server 2022 PKI certificates associated with user accounts must be issued by a DoD PKI or an approved External Certificate Authority (ECA). |
| V-254442 | WN22-PK-000010 | medium | Windows Server 2022 must have the DoD Root Certificate Authority (CA) certificates installed in the Trusted Root Store. |
| V-254443 | WN22-PK-000020 | medium | Windows Server 2022 must have the DoD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems. |
| V-254444 | WN22-PK-000030 | medium | Windows Server 2022 must have the US DOD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems. |
| V-254462 | WN22-SO-000180 | medium | Windows Server 2022 unencrypted passwords must not be sent to third-party Server Message Block (SMB) servers. |
| V-254474 | WN22-SO-000300 | high | Windows Server 2022 must be configured to prevent the storage of the LAN Manager hash of passwords. |
| V-254479 | WN22-SO-000350 | medium | Windows Server 2022 users must be required to enter a password to access private keys stored on the computer. |
| V-257826 | RHEL-09-215015 | high | RHEL 9 must not have a File Transfer Protocol (FTP) server package installed. |
| V-258041 | RHEL-09-411010 | medium | RHEL 9 user account passwords for new users or password changes must have a 60-day maximum password lifetime restriction in /etc/login.defs. |
| V-258042 | RHEL-09-411015 | medium | RHEL 9 user account passwords must have a 60-day maximum password lifetime restriction. |
| V-258091 | RHEL-09-611010 | medium | RHEL 9 must ensure the password complexity module in the system-auth file is configured for three retries or less. |
| V-258097 | RHEL-09-611040 | medium | RHEL 9 must ensure the password complexity module is enabled in the password-auth file. |
| V-258099 | RHEL-09-611050 | medium | RHEL 9 password-auth must be configured to use a sufficient number of hashing rounds. |
| V-258100 | RHEL-09-611055 | medium | RHEL 9 system-auth must be configured to use a sufficient number of hashing rounds. |
| V-258101 | RHEL-09-611060 | medium | RHEL 9 must enforce password complexity rules for the root account. |
| V-258102 | RHEL-09-611065 | medium | RHEL 9 must enforce password complexity by requiring that at least one lowercase character be used. |
| V-258103 | RHEL-09-611070 | medium | RHEL 9 must enforce password complexity by requiring that at least one numeric character be used. |
| V-258104 | RHEL-09-611075 | medium | RHEL 9 passwords for new users or password changes must have a 24 hours minimum password lifetime restriction in /etc/login.defs. |
| V-258105 | RHEL-09-611080 | medium | RHEL 9 passwords must have a 24 hours minimum password lifetime restriction in /etc/shadow. |
| V-258107 | RHEL-09-611090 | medium | RHEL 9 passwords must be created with a minimum of 15 characters. |
| V-258109 | RHEL-09-611100 | medium | RHEL 9 must enforce password complexity by requiring that at least one special character be used. |
| V-258111 | RHEL-09-611110 | medium | RHEL 9 must enforce password complexity by requiring that at least one uppercase character be used. |
| V-258112 | RHEL-09-611115 | medium | RHEL 9 must require the change of at least eight characters when passwords are changed. |
| V-258113 | RHEL-09-611120 | medium | RHEL 9 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed. |
| V-258114 | RHEL-09-611125 | medium | RHEL 9 must require the maximum number of repeating characters be limited to three when passwords are changed. |
| V-258115 | RHEL-09-611130 | medium | RHEL 9 must require the change of at least four character classes when passwords are changed. |
| V-258116 | RHEL-09-611135 | medium | RHEL 9 must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords. |
| V-258117 | RHEL-09-611140 | medium | RHEL 9 must be configured to use the shadow file to store only encrypted representations of passwords. |
| V-258127 | RHEL-09-611190 | medium | RHEL 9, for PKI-based authentication, must enforce authorized access to the corresponding private key. |
| V-258131 | RHEL-09-631010 | medium | RHEL 9, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor. |
| V-258132 | RHEL-09-631015 | medium | RHEL 9 must map the authenticated identity to the user or group account for PKI-based authentication. |
| V-258133 | RHEL-09-631020 | medium | RHEL 9 must prohibit the use of cached authenticators after one day. |
| V-258231 | RHEL-09-671015 | medium | RHEL 9 must employ FIPS 140-3 approved cryptographic hashing algorithms for all stored passwords. |
| V-258233 | RHEL-09-671025 | medium | RHEL 9 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-3 approved cryptographic hashing algorithm for system authentication. |
| V-274883 | CNTR-K8-001161 | high | Sensitive information must be stored using Kubernetes Secrets or an external Secret store provider. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/IA-5. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.