Debian 13 ISM No Complexity Requirement Component Definition

debian-13-pwquality-no-complexity · version 1.0.0 · OSCAL 1.1.2

technically-tested unpublished

Not accredited. Assurance authority: none; self-asserted by the contributing author. Endorsement: none.

Theoretical component. It describes a configuration that satisfies the named controls when applied; it is not an assertion that any particular system is running it. An SSP leveraging this component must supply the implementation evidence for its own hosts.

Assurance state is 'technically-tested': the configuration was applied to a clean Debian 13 install and verified end to end. It has NOT been independently assessed, and is not endorsed or accredited by the ACSC, NIST, or any assessment authority.

Documentcomponent-definition.json
sha256 acda4a964dbaf7b738ee83b2407770cd3564c0edfc92966cdf2dddf38bff3da9
Identityhttps://library.oscalops.net/component-definitions/debian-13-pwquality-no-complexity/1.0.0/component-definition.json
SourceLocal development source — not publishable until pinned to a git commit
VersionsAll versions of debian-13-pwquality-no-complexity

Debian 13 ISM No Complexity Requirement

ism-2080 requires that complexity requirements are NOT imposed. Every character-class credit and the class-count floor are set to zero, so no class is required and none earns credit against a minimum length: length alone governs.

Depends on debian-13-pwquality-base. This is also what keeps debian-13-pwquality-minlen a pure character count.

Purpose. Ensure no character-class complexity requirement is imposed on local Debian accounts.

Properties
os-distributiondebian
os-release13
os-codenametrixie
settingpwquality:dcredit
settingpwquality:ucredit
settingpwquality:lcredit
settingpwquality:ocredit
settingpwquality:minclass

Australian Cyber Security Centre: Information Security Manual v2026.09.4

The ISM prohibition on complexity requirements, as published in the ACSC ISM OSCAL catalogue release v2026.09.4.

ISM-2080 — Password strength

Implemented. dcredit, ucredit, lcredit and ocredit are all 0, so no character class earns credit and none is required; minclass = 0 imposes no class-count floor.

Verified by behaviour: an all-lowercase passphrase at the minimum length in force is accepted, which shows length alone governs.

Remarks

maxrepeat and maxsequence are retained. These are predictability constraints, not character class complexity requirements, so they do not conflict with this control.

Configuration and scripts

Files

ResourceFileSHA-256
No complexity requirementconfig/pwquality.conf.d/50-ism-no-complexity.conf00be92183836d76e209184750f0abbfb9ad1c801b35f4d4a5db22b579413b26c
Apply scriptscripts/apply-no-complexity.sh347a34d6dd460413bdbd4bdd0a05689dc9e347395accad1c2b21bd939dc86c2b
Verification scriptscripts/verify-no-complexity.sh3b119c4f1067d183fc7480c7536aebfbdd7d365ef2536ea4aa1382748171a228

External references