/sbin/authconfig —passminlen=8 —update
/sbin/authconfig —enablereqdigit —update
/sbin/authconfig —enablereqlower —update
/sbin/authconfig —enablerequpper —update
/sbin/authconfig —enablereqother —update
[chroot@test-sftp-server ~]$ grep "^lcredit" /etc/security/pwquality.conflcredit = -1[chroot@test-sftp-server ~]$ ll /etc/security/pwquality.conf-rw-r--r--. 1 root root 1843 Jul 5 09:49 /etc/security/pwquality.conf[chroot@test-sftp-server ~]$ cat /etc/security/pwquality.conf# Configuration for systemwide password quality limits# Defaults:## Number of characters in the new password that must not be present in the# old password.# difok = 5## Minimum acceptable size for the new password (plus one if# credits are not disabled which is the default). (See pam_cracklib manual.)# Cannot be set to lower value than 6.# minlen = 9## The maximum credit for having digits in the new password. If less than 0# it is the minimum number of digits in the new password.# dcredit = 1## The maximum credit for having uppercase characters in the new password.# If less than 0 it is the minimum number of uppercase characters in the new# password.# ucredit = 1## The maximum credit for having lowercase characters in the new password.# If less than 0 it is the minimum number of lowercase characters in the new# password.# lcredit = 1## The maximum credit for having other characters in the new password.# If less than 0 it is the minimum number of other characters in the new# password.# ocredit = 1## The minimum number of required classes of characters for the new# password (digits, uppercase, lowercase, others).# minclass = 0## The maximum number of allowed consecutive same characters in the new password.# The check is disabled if the value is 0.# maxrepeat = 0## The maximum number of allowed consecutive characters of the same class in the# new password.# The check is disabled if the value is 0.# maxclassrepeat = 0## Whether to check for the words from the passwd entry GECOS string of the user.# The check is enabled if the value is not 0.# gecoscheck = 0## Path to the cracklib dictionaries. Default is to use the cracklib default.# dictpath =minlen = 8minclass = 1maxrepeat = 0maxclassrepeat = 0lcredit = -1ucredit = -1dcredit = -1ocredit = -1[chroot@test-sftp-server ~]$
[chroot@test-sftp-server ~]$ cat /etc/login.defs |grep PASS_MAX_DAYS# PASS_MAX_DAYS Maximum number of days a password may be used.PASS_MAX_DAYS 90[chroot@test-sftp-server ~]$
