STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← Back to Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide

V-260564

CAT II (Medium)

Ubuntu 22.04 LTS must prevent the use of dictionary words for passwords.

Rule ID

SV-260564r991587_rule

STIG

Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide

Version

V2R8

CCIs

CCI-000366

Discussion

If Ubuntu 22.04 LTS allows the user to select passwords based on dictionary words, then this increases the chances of password compromise by increasing the opportunity for successful guesses and brute-force attacks.

Check Content

Verify Ubuntu 22.04 LTS prevents the use of dictionary words for passwords by using the following command: 
 
     $ grep -i dictcheck /etc/security/pwquality.conf 
     dictcheck = 1  
  
If "dictcheck" is not set to "1", is commented out, or is missing, this is a finding.

Fix Text

Configure Ubuntu 22.04 LTS to prevent the use of dictionary words for passwords. 
  
Add or modify the following line in the "/etc/security/pwquality.conf" file: 
  
dictcheck = 1