Not accredited. Assurance authority: none; self-asserted by the contributing author. Endorsement: none.
Theoretical component. It describes a configuration that satisfies the named controls when applied; it is not an assertion that any particular system is running it. An SSP leveraging this component must supply the implementation evidence for its own hosts.
Assurance state is 'technically-tested': the configuration was applied to a clean Debian 13 install and verified end to end. It has NOT been independently assessed, and is not endorsed or accredited by the ACSC, NIST, or any assessment authority.
Debian 13 ISM No Complexity Requirement
ism-2080 requires that complexity requirements are NOT imposed. Every character-class credit and the class-count floor are set to zero, so no class is required and none earns credit against a minimum length: length alone governs.
Depends on debian-13-pwquality-base. This is also what keeps debian-13-pwquality-minlen a pure character count.
Purpose. Ensure no character-class complexity requirement is imposed on local Debian accounts.
Properties
| os-distribution | debian |
|---|
| os-release | 13 |
|---|
| os-codename | trixie |
|---|
| setting | pwquality:dcredit |
|---|
| setting | pwquality:ucredit |
|---|
| setting | pwquality:lcredit |
|---|
| setting | pwquality:ocredit |
|---|
| setting | pwquality:minclass |
The ISM prohibition on complexity requirements, as published in the ACSC ISM OSCAL catalogue release v2026.09.4.
ISM-2080 — Password strength
Implemented. dcredit, ucredit, lcredit and ocredit are all 0, so no character class earns credit and none is required; minclass = 0 imposes no class-count floor.
Verified by behaviour: an all-lowercase passphrase at the minimum length in force is accepted, which shows length alone governs.
Remarks
maxrepeat and maxsequence are retained. These are predictability constraints, not character class complexity requirements, so they do not conflict with this control.
Configuration and scripts