The CA-ACF2 PSWD GSO record values for MAXTRY and PASSLMT must be properly set.
DISA Rule
SV-223462r533198_rule
Vulnerability Number
V-223462
Group Title
SRG-OS-000329-GPOS-00128
Rule Version
ACF2-ES-000430
Severity
CAT II
CCI(s)
- CCI-002238 - The information system automatically locks the account or node for either an organization-defined time period, until the locked account or node is released by an administrator, or delays the next logon prompt according to the organization-defined delay algorithm when the maximum number of unsuccessful logon attempts is exceeded.
Weight
10
Fix Recommendation
Configure the GSO option "MAXTRY" to equal "3".
Configure the GSO option "PASSLMT" to equal "3".
Check Contents
From an ACF command screen enter:
SET CONTROL(GSO)
SHOW PSwdopts
If "MAXTRY" is set to "3", this is not a finding.
If "PASSLMT" is set to "3", this is not a finding.
Vulnerability Number
V-223462
Documentable
False
Rule Version
ACF2-ES-000430
Severity Override Guidance
From an ACF command screen enter:
SET CONTROL(GSO)
SHOW PSwdopts
If "MAXTRY" is set to "3", this is not a finding.
If "PASSLMT" is set to "3", this is not a finding.
Check Content Reference
M
Target Key
4100
Comments