Skip to content

Add password policy module (libpam-pwquality) #4

Description

@ranjith-src

What

Add a password module that installs libpam-pwquality and writes /etc/security/pwquality.conf with sensible defaults (minlen=12, complexity requirements).

Why

Even with key-only SSH, passwords still matter for:

  • sudo authentication
  • su to switch users
  • Console/VNC access from VPS provider dashboard
  • Any PAM-authenticated service

A weak password on the deploy user means an attacker who gains any foothold can escalate via sudo.

Suggested implementation

Install libpam-pwquality and write config:

# /etc/security/pwquality.conf
minlen = 12
dcredit = -1
ucredit = -1
lcredit = -1
ocredit = -1
enforce_for_root

Add verification: check that libpam-pwquality is installed and config file exists with expected minlen.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions