What is the impact of removing nullok from pam_unix.so in RHEL PAM configuration?
Issue
- Removal of
nullokfrompam_unixmodule in thesystem-authandpassword-authfiles can cause any risk ? - Evaluating the removal of the nullok option from
pam_unix.sofor security compliance. - Need to understand the operational and security implications of this change.
- Removing
nullokimproves security but may introduce login failures for users with blank passwords. - This change is recommended for CIS compliance, STIG alignment, or general hardening practices.
- Need to understand the operational and security implications of this change.
- Seeking guidance to safely audit and remove
nullokfrom the PAM configuration.
Environment
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- PAM
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.