Passwords appearing in lists of commonly used passwords or lists of compromised passwords are not used.
ISM-2078
Password strength
Australian Cyber Security Centre · Information Security Manual v2026.09.4 · Applicability NC, OS, P, S, TS
Components addressing ISM-2078
partial Applicability claimed: NC, OS, P, S, TS
Partially implemented. dictcheck = 1 evaluates every candidate against the cracklib dictionary, and badwords rejects organisation-specific terms.
Measured on a clean Debian 13 install, with candidates padded to at or above the minimum length in force so that length cannot be the reason for rejection: 1 of 8 common breach-list passwords was rejected at a 15-character minimum, and 2 of 8 at 20. The stock cracklib dictionary is a common-word corpus, not a breach-credential corpus, so the substantive requirement is not met by this configuration alone.
Residual risk Measured: only 1 of 8 long common passwords rejected at minlen 15. cracklib is not a breach-credential corpus.
Configuration and scripts
- config/pwquality.conf.d/50-ism-dictionary.conf Dictionary checking
sha256 b76d29e7513a886b43006369cf06962fffeaedca3c08d618765b2935e999b8e7 - scripts/verify-dictionary.sh Verification script
sha256 ed412adeb309d9b3bd61593e666437a97f3f61d4f50c477bce76eaf8a601221b
This control's implementations as an OSCAL component definition (newest version of each component)