You should just have your system utilize a password complexity requirement and skip all this stupid auditing.

cheers,

catch