The delay between login prompts following a failed login attempt must be at least 4 seconds.
DISA Rule
SV-220075r603266_rule
Vulnerability Number
V-220075
Group Title
SRG-OS-000329
Rule Version
GEN000480
Severity
CAT II
CCI(s)
- CCI-002238 - The information system automatically locks the account or node for either an organization-defined time period, until the locked account or node is released by an administrator, or delays the next logon prompt according to the organization-defined delay algorithm when the maximum number of unsuccessful logon attempts is exceeded.
Weight
10
Fix Recommendation
Edit the /etc/default/login file and set SLEEPTIME to 4.
Check Contents
Check the SLEEPTIME parameter in the /etc/default/login file.
# grep SLEEPTIME /etc/default/login
If SLEEPTIME is not listed, commented out, or less than 4, this is a finding.
Vulnerability Number
V-220075
Documentable
False
Rule Version
GEN000480
Severity Override Guidance
Check the SLEEPTIME parameter in the /etc/default/login file.
# grep SLEEPTIME /etc/default/login
If SLEEPTIME is not listed, commented out, or less than 4, this is a finding.
Check Content Reference
M
Target Key
4061
Comments