Security FAQ
The OS keeps rejecting my password. What do I need to do?
The password selection criteria is defined by DISA and is subject to change. For more information about DISA password conventions, see the DISA STIG for the latest Red Hat version at http://iase.disa.mil.
For a complete list and details refer to the reports provided as part of the ASTi IA Package or IA Maintenance program deliverable(s).
The following User Account Control requirements apply to ASTi Security Software Versions 1.7-1 and after:
- Three Failed Login Attempts - After 3 failed attempts to login, you are permanently logged out.
- Inactivity Timeout - You are automatically logged out after 15 minutes of inactivity.
- Password Change 24 Hours - A user cannot change the password more than once every 24 hours.
- Password Length - Shall be 14 characters or more.
- Password Character Mix - At a minimum a user must have 1 Upper Case, 1 Lower Case, 1 Number and 1 Special Characters (#$%ˆ&).
- Password Contents - No names, telephone numbers, account names, dictionary words, etc.
- Password Change Every 60 Days - Password must be changed every 60 days.
- Inactive Accounts are locked - After 35 days of no login the account will be locked.
- Easily Guessed Passwords - Easily guessed passwords cannot be used.
- Password Reuse - Cannot reuse any of the previous 5 password entries.
Passwords that include any of the following will be rejected:
- Password is a palindrome.
- Password is the same or too similar to one of the 5 previous passwords (not enough different characters).
- Password is one of the 5 previous passwords but rotated.
- Password is too simple (doesn't contain enough different characters or contains a sequence of characters).
- Password is too simple (i.e. doesn't contain enough different character types - lower case, upper case, numeric, and special characters).
Password is based upon username or modified version of username (username rotated, backwards, or spelled in hacker "leet" speak.
- Password contains a sequence of keys which appear next to each other on the keyboard.
- Password is all whitespace.
- Password contains a word which appears in dictionary either forwards or backwards.
- Password contains a word spelled in hacker "leet" speak which appears in dictionary either forwards or backwards.
The following User Account Control requirements apply to ASTi Security Software Versions 1.6-1 and prior:
- Three Failed Login Attempts - After 3 failed attempts to login, you are permanently logged out.
- Inactivity Timeout - You are automatically logged out after 15 minutes of inactivity.
- Password Change 24 Hours - A user cannot change the password more than once every 24 hours.
- Password Length - Shall be 14 characters or more.
- Password Character Mix - At a minimum a user must have 2 Upper Case, 2 Lower Case, 2 Number and 2 Special Character (#$%ˆ&).
-
- Password Contents - No names, telephone numbers, account names, dictionary words, etc.
- Password Change Every 60 Days - Password must be changed every 60 days
- Inactive Accounts are locked - After 35 days of no login the account will be locked.
- Easily Guessed Passwords - Easily guessed passwords cannot be used
- Password Reuse - Cannot reuse any of the previous 5 password entries