ÔõÑùÔÚLinuxÉÏÉèÖÃÇå¾²ÐÔÇ¿µÄÃÜÂëÕ½ÂÔ
ÔõÑùÔÚlinuxÉÏÉèÖÃÇå¾²ÐÔÇ¿µÄÃÜÂëÕ½ÂÔ
СÐò:
ÔÚÐÅϢʱ´ú£¬±£»¤Ð¡ÎÒ˽È˺ÍÆóÒµµÄÃô¸ÐÐÅÏ¢ÊÇÖÁ¹ØÖ÷ÒªµÄ¡£¶øÃÜÂëÔòÊÇ×î³£ÓõÄÉí·ÝÑéÖ¤·½·¨Ö®Ò»¡£
ÔÚLinuxϵͳÖУ¬ÎÒÃÇ¿ÉÒÔͨ¹ýÉèÖÃÇ¿Ê¢µÄÃÜÂëÕ½ÂÔÀ´ÔöÌíÕË»§ÃÜÂëµÄÇå¾²ÐÔ£¬´Ó¶ø±£»¤ÎÒÃǵÄÅÌËã»úºÍÊý¾ÝµÄÇå¾²¡£
±¾ÎĽ«ÏÈÈÝÔõÑùÔÚlinuxÉÏÉèÖÃÇå¾²ÐÔÇ¿µÄÃÜÂëÕ½ÂÔ£¬²¢¸½ÉÏÏà¹Ø´úÂëʾÀý¡£
ÐÞ¸ÄÃÜÂëÕ½ÂÔÎļþ
Ê×ÏÈ£¬ÎÒÃÇÐèÒª±à¼ÃÜÂëÕ½ÂÔÎļþ/etc/login.defs¡£¸ÃÎļþ°üÀ¨ÁËÓëÕË»§ÃÜÂëÏà¹ØµÄÖÖÖÖÉèÖÃÑ¡Ïî¡£
ʹÓÃÎı¾±à¼Æ÷·¿ª¸ÃÎļþ£¬²¢ÕÒµ½ÒÔÏÂÐУº
PASS_MAX_DAYS 99999
PASS_MIN_DAYS 0 ÍêÕûʾÀý´úÂ룺
sudo vi /etc/login.defs
µÇ¼ºó¸´ÖÆ
ÉèÖÃÃÜÂëÓÐÓÃÆÚ
ÔÚÃÜÂëÕ½ÂÔÎļþÖУ¬Í¨¹ýÐÞ¸ÄPASS_MAX_DAYS²ÎÊýÀ´ÉèÖÃÃÜÂëµÄÓÐÓÃÆÚ¡£½«ÆäÐÞ¸ÄΪһ¸ö½ÏСµÄÖµ£¬Èç90Ìì¡£
ʾÀý´úÂ룺
# ÉèÖÃÃÜÂëÓÐÓÃÆÚΪ90Ìì PASS_MAX_DAYS 90
µÇ¼ºó¸´ÖÆ
ÉèÖÃÃÜÂë×îСʹÓÃÏÞÆÚ
ͬÑùÔÚÃÜÂëÕ½ÂÔÎļþÖУ¬Í¨¹ýÐÞ¸ÄPASS_MIN_DAYS²ÎÊýÀ´ÉèÖÃÃÜÂëµÄ×îСʹÓÃÏÞÆÚ¡£
ÕâÒâζ×ÅÓû§±ØÐèÔÚÐÞ¸ÄÃÜÂëºóµÄÈô¸ÉÌìºó²Å»ªÔÙ´ÎÐÞ¸ÄÃÜÂ룬ÉèÖÃÒ»¸ö½Ï´óµÄÖµÓÐÖúÓÚ±ÜÃâÓû§ÆµÈÔ¸ü¸ÄÃÜÂë¡£
ʾÀý´úÂ룺
# ÉèÖÃÃÜÂë×îСʹÓÃÏÞÆÚΪ7Ìì PASS_MIN_DAYS 7
µÇ¼ºó¸´ÖÆ
ÉèÖÃÃÜÂë×îС³¤¶È
ÃÜÂëµÄ³¤¶ÈÊÇÒ»¸öÒªº¦µÄÇå¾²ÒòËØ¡£ÔÚÃÜÂëÕ½ÂÔÎļþÖУ¬ÎÒÃÇ¿ÉÒÔͨ¹ýÐÞ¸ÄPASS_MIN_LEN²ÎÊýÀ´ÉèÖÃÃÜÂëµÄ×îС³¤¶È¡£
½¨Ò齫ÆäÉèÖÃΪÖÁÉÙ8λ×Ö·û¡£
ʾÀý´úÂ룺
# ÉèÖÃÃÜÂë×îС³¤¶ÈΪ8λ PASS_MIN_LEN 8
µÇ¼ºó¸´ÖÆ
ÉèÖÃÃÜÂëÇ¿¶È¼ì²éÕ½ÂÔ
ÈÃÓû§Ñ¡Ôñ¾ß±¸Ò»¶¨Ç¿¶ÈµÄÃÜÂëÒ²ÊÇÒ»ÖÖÓÐÓõÄÇå¾²ÊֶΡ£ÔÚLinuxÖУ¬ÎÒÃÇ¿ÉÒÔͨ¹ý×°Öò¢ÉèÖÃpam_cracklibÄ£¿éÀ´ÊµÏÖÃÜÂëÇ¿¶È¼ì²é¡£
Ê×ÏÈ£¬ÎÒÃÇÐèҪװÖøÃÄ£¿é£º
sudo apt-get install libpam-cracklib
µÇ¼ºó¸´ÖÆ
È»ºó£¬ÎÒÃÇÐèÒª±à¼pamÉèÖÃÎļþ/etc/pam.d/common-password£¬²¢ÔÚÎļþÖÐÌí¼ÓÒÔÏÂÐУº
# ÃÜÂëÇ¿¶È¼ì²é password requisite pam_cracklib.so retry=3 minlen=8 difok=3
µÇ¼ºó¸´ÖÆ
´Ë´¦µÄ²ÎÊýretryÌåÏÖµ±Óû§ÊäÈëÈõÃÜÂëʱ£¬ÏµÍ³ÒªÇóÓû§ÖØÐÂÊäÈëÃÜÂëµÄ´ÎÊý¡£
²ÎÊýminlenÌåÏÖ×îСÃÜÂ볤¶È£¬½¨ÒéÓë֮ǰÉèÖõÄPASS_MIN_LENÏàͬ¡£
²ÎÊýdifokÌåÏÖÃÜÂëÖÐÖÁÉÙÒª°üÀ¨¼¸¶à¸ö²î±ðµÄ×Ö·û¡£
Ç¿ÖÆÒªÇóÓû§Ê¹ÓÃÖØ´óÃÜÂë
ΪÁËÈ·±£Óû§½¨ÉèÇ¿ÃÜÂ룬ÎÒÃÇ¿ÉÒÔͨ¹ýÉèÖÃpassword requisiteÐеIJÎÊýdcredit¡¢ucredit¡¢lcreditºÍocreditÀ´Ç¿ÖÆÒªÇóÓû§Ê¹ÓÃÖØ´óÃÜÂë¡£
ÕâЩ²ÎÊý»®·Ö¶ÔÓ¦Êý×Ö¡¢´óд×Öĸ¡¢Ð¡Ð´×ÖĸºÍÌØÊâ×Ö·û¡£
ÒÔÏÂΪһ¸öʾÀý´úÂ룺
# ÃÜÂëÇ¿¶È¼ì²é password requisite pam_cracklib.so retry=3 minlen=8 difok=3 dcredit=-1 ucredit=-1 lcredit=-1 ocredit=-1
µÇ¼ºó¸´ÖÆ
ÐÞ¸ÄÃÜÂëÓâÆÚÖÒÑÔÏÞÆÚ
ÔÚÃÜÂëÕ½ÂÔÎļþÖУ¬ÎÒÃÇ¿ÉÒÔͨ¹ýÐÞ¸ÄPASS_WARN_AGE²ÎÊýÀ´ÉèÖÃÃÜÂëÓâÆÚÇ°µÄÖÒÑÔÏÞÆÚ¡£
½«ÆäÉèÖÃΪһ¸öºÏÊʵÄÖµ£¬ÒÔ±ãÌáÌõ¼þÐÑÓû§ÐÞ¸ÄÃÜÂë¡£
ʾÀý´úÂ룺
# ÉèÖÃÃÜÂëÓâÆÚÇ°µÄÖÒÑÔÏÞÆÚΪ7Ìì PASS_WARN_AGE 7
µÇ¼ºó¸´ÖÆ
Ç¿ÖÆÃÜÂëÐÞ¸Ä
×îºó£¬ÎÒÃÇ¿ÉÒÔʹÓÃchageÏÂÁîÀ´Ç¿ÖÆÓû§ÔÚÏ´εǼʱÐÞ¸ÄÃÜÂë¡£
ʾÀý´úÂ룺
# Ç¿ÖÆÓû§ÔÚÏ´εǼʱÐÞ¸ÄÃÜÂë sudo chage -d 0 username
µÇ¼ºó¸´ÖÆ
×ܽá:
ͨ¹ý¶ÔLinuxϵͳÉϵÄÃÜÂëÕ½ÂÔ¾ÙÐÐÊʵ±µ÷½âºÍÓÅ»¯£¬ÎÒÃÇ¿ÉÒÔÔöÌíÕË»§ÃÜÂëµÄÇå¾²ÐÔ¡£
ÉÏÊöÏÈÈݵİ취°üÀ¨ÐÞ¸ÄÃÜÂëÓÐÓÃÆÚ¡¢×îСʹÓÃÏÞÆںͳ¤¶È£¬ÉèÖÃÃÜÂëÇ¿¶È¼ì²éÕ½ÂÔÒÔ¼°Ç¿ÖÆÃÜÂëÐ޸ĵȡ£
ͨ¹ý×ñÕÕÕâЩ°ì·¨£¬²¢ÍŽáÏÖÕæÏàÐξÙÐÐÊʵ±µ÷½â£¬ÎÒÃÇ¿ÉÒÔÌá¸ßÃÜÂëµÄÇå¾²ÐÔ£¬²¢ÓÐÓñ£»¤ÏµÍ³ºÍÊý¾ÝµÄÇå¾²¡£
²Î¿¼×ÊÁÏ:
https://www.tecmint.com/securing-linux-desktops-by-strengthening-passwords/
https://linuxize.com/post/how-to-disable-password-expiration-in-linux/
ÒÔÉϾÍÊÇÔõÑùÔÚLinuxÉÏÉèÖÃÇå¾²ÐÔÇ¿µÄÃÜÂëÕ½ÂÔµÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡