Maximum length limits for passwords are not less than 64 characters.
ISM-2079
Password strength
Australian Cyber Security Centre · Information Security Manual v2026.09.4 · Applicability NC, OS, P, S, TS
Components addressing ISM-2079
implemented Applicability claimed: NC, OS, P, S, TS
Implemented by omission. Neither pam_pwquality nor any drop-in in this family configures a maximum length, and pam_unix uses yescrypt, which does not truncate. The effective ceiling is the PAM response buffer, far above the 64-character floor this control requires.
Verified: a 72-character passphrase is accepted by pwscore(1).
Configuration and scripts
- config/pwquality.conf.d/40-ism-base.conf pwquality enforcement base
sha256 12441639cb0cfea4b0e7df729d5b39877ce73b79e5e47ee3be3c376f1da1825d - scripts/verify-pwquality-base.sh Verification script
sha256 0b54efd7ea49a3addc5d3eb5f4630102e05dca614372e038b8a5d8fb2e67147a
This control's implementations as an OSCAL component definition (newest version of each component)