STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← Back to Juniper SRX Services Gateway NDM Security Technical Implementation Guide

V-223218

CAT II (Medium)

For local accounts using password authentication (i.e., the root account and the account of last resort), the Juniper SRX Services Gateway must enforce password complexity by setting the password change type to character sets.

Rule ID

SV-223218r1015753_rule

STIG

Juniper SRX Services Gateway NDM Security Technical Implementation Guide

Version

V3R3

CCIs

CCI-004066CCI-000192

Discussion

Use of a complex passwords helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. The password change-type command specifies whether a minimum number of character-sets or a minimum number of character-set transitions are enforced. The DOD requires this setting be set to character-sets.

Check Content

Verify the default local password enforces password complexity by setting the password change type to character sets.

[edit]
show system login password

If the password change-type is not set to character-sets, this is a finding.

Fix Text

Configure the default local password to enforce password complexity by setting the password change type to character sets.

[edit]
set system login password change-type character-sets