cyber-0 updated with more examples
This commit is contained in:
@@ -137,7 +137,7 @@
|
||||
'requirement': 'SR 1.5 — Authenticator Strength',
|
||||
'description': 'Password minimum length shall be ≥ 14 characters',
|
||||
'passed': (
|
||||
_minlen.stdout | regex_search('minlen\s*=\s*([0-9]+)') | regex_replace('minlen\s*=\s*', '') | int >= 14
|
||||
(_minlen.stdout | regex_search('minlen\s*=\s*(\d+)', '\1') | default(['0'], true) | first | int) >= 14
|
||||
),
|
||||
'expected': 'minlen >= 14 in /etc/security/pwquality.conf',
|
||||
'actual': _minlen.stdout | trim,
|
||||
@@ -194,7 +194,11 @@
|
||||
'category': 'FR1 - Identification and Authentication Control',
|
||||
'requirement': 'SR 1.7 — Password Lifetime',
|
||||
'description': 'Password maximum age shall be ≤ 90 days',
|
||||
'passed': (_max_days.stdout | trim | int <= 90),
|
||||
'passed': (
|
||||
_max_days.stdout | trim | regex_search('^[0-9]+$') and
|
||||
(_max_days.stdout | trim | int > 0) and
|
||||
(_max_days.stdout | trim | int <= 90)
|
||||
),
|
||||
'expected': 'PASS_MAX_DAYS ≤ 90',
|
||||
'actual': 'PASS_MAX_DAYS=' + (_max_days.stdout | trim | default('NOT SET', true)),
|
||||
'severity': 'medium',
|
||||
|
||||
Reference in New Issue
Block a user