SV-99313r1_rule
V-88663
SRG-OS-000329-GPOS-00128
VROM-SL-001010
CAT III
10
Edit "/etc/pam.d/common-auth" file and add the following line:
auth required pam_tally2.so deny=3 onerr=fail even_deny_root unlock_time=86400 root_unlock_time=300
Edit "/etc/pam.d/common-account" file and add the following line:
account required pam_tally2.so
Check the "pam_tally2" configuration:
# more /etc/pam.d/common-auth
Confirm the following line is configured:
auth required pam_tally2.so deny=3 onerr=fail even_deny_root unlock_ti
me=86400 root_unlock_time=300
# more /etc/pam.d/common-account
Confirm the following line is configured:
account required pam_tally2.so
If no such lines are found, this is a finding.
V-88663
False
VROM-SL-001010
Check the "pam_tally2" configuration:
# more /etc/pam.d/common-auth
Confirm the following line is configured:
auth required pam_tally2.so deny=3 onerr=fail even_deny_root unlock_ti
me=86400 root_unlock_time=300
# more /etc/pam.d/common-account
Confirm the following line is configured:
account required pam_tally2.so
If no such lines are found, this is a finding.
M
3461