diff --git a/defaults/main.yml b/defaults/main.yml index 4245f53c..5be5f911 100644 --- a/defaults/main.yml +++ b/defaults/main.yml @@ -1104,7 +1104,7 @@ rhel9cis_passwd_dictcheck_file: etc/security/pwquality.conf.d/50-pwdictcheck.con rhel9cis_passwd_dictcheck_value: 1 # 5.3.3.2.7 - Ensure password quality is enforced for the root user -rhel9cis_passwd_quality_enforce_file: etc/security/pwquality.conf.d/50-pwquality_enforce.conf # pragma: allowlist secret +rhel9cis_passwd_quality_enforce_file: etc/security/pwquality.conf.d/50-pwroot.conf # pragma: allowlist secret rhel9cis_passwd_quality_enforce_value: 1 rhel9cis_passwd_quality_enforce_root_value: enforce_for_root # pragma: allowlist secret diff --git a/tasks/section_5/cis_5.3.3.2.x.yml b/tasks/section_5/cis_5.3.3.2.x.yml index aa2e0f84..a53d857b 100644 --- a/tasks/section_5/cis_5.3.3.2.x.yml +++ b/tasks/section_5/cis_5.3.3.2.x.yml @@ -340,7 +340,7 @@ - system notify: Authselect update -- name: "5.3.3.2.7 | PATCH | Ensure password quality checking is enforced" +- name: "5.3.3.2.7 | PATCH | Ensure password quality is enforced for the root user" when: rhel9cis_rule_5_3_3_2_7 tags: - level1-server