Ensure PAM Enforces Password Requirements - Minimum Special Characters
Forces pam_pwquality to require at least one special ("other") character in every new password by setting ocredit = -1.
Checked against the content of a persistent configuration file, the source of truth that survives reboots.
A mapping is a cross-reference to where each standard places this requirement, anchored and cross-validated, not a claim of equivalence. A passing check is evidence toward these references, how to read it.
Why this rule matters
A complex password increases the time and resources needed to compromise it. The ocredit parameter controls how special characters (punctuation, symbols) count toward strength: a value of -1 makes at least one special character mandatory. Special characters dramatically enlarge the per-position search space, making brute-force and dictionary attacks much costlier. Without it, passwords limited to letters and digits fall far faster.
What Pavois checks
Pavois reads the effective ocredit value across /etc/security/pwquality.conf and all drop-ins under /etc/security/pwquality.conf.d/, keeping the last definition that wins at runtime. A scanner reading only the main file would miss an override placed in a drop-in. The control passes only when the resolved value is <= -1.
describe command('v=$(grep -rh \'^[[:space:]]*ocredit[[:space:]]*=\' /etc/security/pwquality.conf /etc/security/pwquality.conf.d/ 2>/dev/null | tail -1 | grep -oE \'[-]?[0-9]+\'); { [ -n "$v" ] && [ "$v" -le -1 ] && echo ok; } || echo ko') do
its('stdout.strip') { should eq 'ok' }
endHow to verify it is applied
Run grep -rh '^[[:space:]]*ocredit' /etc/security/pwquality.conf /etc/security/pwquality.conf.d/ | tail -1. The effective line must read ocredit = -1 (or any value <= -1).
Inspect & investigate
Password changes rejected for lacking a special character are logged via PAM in /var/log/auth.log (Debian/Ubuntu) or /var/log/secure (RHEL family) with pam_pwquality messages. Inspect the live setting with grep -r ocredit /etc/security/pwquality.conf.d/.
Remediation
pavois harden apply writes ocredit = -1 to the drop-in /etc/security/pwquality.conf.d/99-Pavois.conf via the idempotent keyval resource. The 99- prefix ensures it overrides any earlier value. No service restart is needed; it applies at the next password change.
Pavois applies this with its own harden engine, the plan below, not a shell script:
| file | /etc/security/pwquality.conf.d/99-pavois.conf |
|---|---|
| key | ocredit |
| resource | keyval |
| value | -1 |
pavois harden plan localwhere the target is local, a user@host SSH alias, or a container , Docs
Impact & precautions
Existing passwords remain valid; only new passwords must include a special character. Users choosing alphanumeric-only passwords will be rejected. Lockout risk is low, but ensure automated provisioning and rotation tooling emit passwords with at least one symbol before applying, and note that some legacy systems restrict the symbol set in shared credentials.
Standards mapping
| Standard | Reference | Type | Version | Confidence |
|---|---|---|---|---|
| ANSSI BP-028 | R31 | direct | 2.0 | high |
| CIS | 5.3.3.2.3 | direct | per OS, see the benchmark table | high |
| NIST | CM-6(a), IA-5(1)(a), IA-5(4), IA-5(c) | supporting | 800-53 Rev 5 · 800-171 Rev 2 (pinned) | medium |
| DISA STIG | UBTU-22-611025, UBTU-24-400330 | direct | per OS STIG release | high |
Each reference is a cross-reference anchored in the upstream benchmark and cross-validated against the SCAP Security Guide and ansible-lockdown, not a claim of equivalence. Direct = a prescriptive, line-level requirement; supporting = an abstract control family (NIST) the check provides evidence toward. How to read a mapping.