官术网_书友最值得收藏!

Hands-on lab for setting password complexity criteria

For this lab, you can use either the CentOS or Ubuntu virtual machine, as desired. The only difference is that you won't perform Step 1 for CentOS:

  1. For Ubuntu only, install the libpam-pwquality package:
    sudo apt install libpam-pwquality
  1. Open the /etc/security/pwquality.conf file in your preferred text editor. Remove the comment symbol from in front of the minlen line and change the value to 19. It should now look like this:
        minlen = 19

Save the file and exit the editor.

  1. Create a user account for Goldie and attempt to assign her the passwords, turkeylips, TurkeyLips, and Turkey93Lips. Note the change in each warning message.
  2. In the pwquality.conf file, comment out the minlen line. Uncomment the minclass line and the maxclassrepeat line. Change the maxclassrepeat value to 5. The lines should now look like:
        minclass = 3
maxclassrepeat = 5

Save the file and exit the text editor.

  1. Try assigning various passwords that don't meet the complexity criteria that you've set to Goldie's account and view the results.

In the /etc/login.defs file on your CentOS machine, you'll see the line:

PASS_MIN_LEN    5

Supposedly, this is to set the minimum password length, but in reality, pwquality overrides it. So, you could set this value to anything at all, and it would have no effect.

主站蜘蛛池模板: 新营市| 祥云县| 林周县| 霍州市| 阳高县| 邯郸县| 瑞丽市| 荣昌县| 齐河县| 冀州市| 布拖县| 武平县| 吉木萨尔县| 托克逊县| 元阳县| 乌兰察布市| 定兴县| 青海省| 永新县| 兴宁市| 仲巴县| 虹口区| 资溪县| 田林县| 甘德县| 宁都县| 商河县| 新宁县| 盈江县| 石渠县| 德昌县| 涪陵区| 钟山县| 常德市| 随州市| 双峰县| 叙永县| 潮安县| 长垣县| 河间市| 瑞昌市|