RHCSA Rapid Track
In this exercise, you will set password policies for several users.
Outcomes
You should be able to:
Force a password change when the user logs in to the system for the first time.
Force a password change every 90 days.
Set the account to expire 180 days from the current day.
Log in to workstation as student using student as the password.
On workstation, run lab users-pw-manage start to start the exercise.
This script creates the necessary user accounts and files to ensure that the environment is set up correctly.
[student@workstation ~]$lab users-pw-manage start
From
workstation, open an SSH session toserveraasstudent.[student@workstation ~]$ssh student@servera...output omitted...[student@servera ~]$On
servera, explore locking and unlocking user accounts asstudent.As
student, lock theoperator1account using administrative rights.[student@servera ~]$sudo usermod -L operator1[sudo] password for student:studentAttempt to log in as
operator1. This should fail.[student@servera ~]$su - operator1Password:redhatsu: Authentication failureUnlock the
operator1account.[student@servera ~]$sudo usermod -U operator1Attempt to log in as
operator1again. This should succeed.[student@servera ~]$su - operator1Password:redhat...output omitted...[operator1@servera ~]$Exit out of the
operator1user's shell to return to thestudentuser's shell.[operator1@servera ~]$exitlogout
Change the password policy for
operator1to require a new password every 90 days. Confirm that the password age is successfully set.Set the maximum age of the
operator1user's password to 90 days.[student@servera ~]$sudo chage -M 90 operator1Verify that the
operator1user's password expires 90 days after it is changed.[student@servera ~]$sudo chage -l operator1Last password change : Jan 25, 2019 Password expires : Apr 25, 2019 Password inactive : never Account expires : never Minimum number of days between password change : 0Maximum number of days between password change : 90Number of days of warning before password expires : 7
Force a password change on the first login for the
operator1account.[student@servera ~]$sudo chage -d 0 operator1Log in as
operator1and change the password toforsooth123. After setting the password, return to thestudentuser's shell.Log in as
operator1and change the password toforsooth123when prompted.[student@servera ~]$su - operator1Password:redhatYou are required to change your password immediately (administrator enforced)Current password:redhatNew password:forsooth123Retype new password:forsooth123...output omitted...[operator1@servera ~]$Exit the
operator1user's shell to return to thestudentuser's shell.[operator1@servera ~]$exitlogout
Set the
operator1account to expire 180 days from the current day. Hint: The date -d "+180 days" gives you the date and time 180 days from the current date and time.Determine a date 180 days in the future. Use the format
%Fwith the date command to get the exact value.[student@servera ~]$date -d "+180 days" +%F2019-07-24You may get a different value to use in the following step based on the current date and time in your system.
Set the account to expire on the date displayed in the preceding step.
[student@servera ~]$sudo chage -E2019-07-24operator1Verify that the account expiry date is successfully set.
[student@servera ~]$sudo chage -l operator1Last password change : Jan 25, 2019 Password expires : Apr 25, 2019 Password inactive : neverAccount expires : Jul 24, 2019Minimum number of days between password change : 0 Maximum number of days between password change : 90 Number of days of warning before password expires : 7
Set the passwords to expire 180 days from the current date for all users. Use administrative rights to edit the configuration file.
Set
PASS_MAX_DAYSto180in/etc/login.defs. Use administrative rights when opening the file with the text editor. You can use the sudo vim /etc/login.defs command to perform this step....output omitted... # Password aging controls: # # PASS_MAX_DAYS Maximum number of days a password may be # used. # PASS_MIN_DAYS Minimum number of days allowed between # password changes. # PASS_MIN_LEN Minimum acceptable password length. # PASS_WARN_AGE Number of days warning given before a # password expires. #
PASS_MAX_DAYS 180PASS_MIN_DAYS 0 PASS_MIN_LEN 5 PASS_WARN_AGE 7 ...output omitted...Important
The default password and account expiry settings will be effective for new users but not for existing users.
Log off from
servera.[student@servera ~]$exitlogout Connection to servera closed.[student@workstation ~]$