STIGQter STIGQter: STIG Summary: VMware vRealize Operations Manager 6.x SLES Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

The SLES for vRealize must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes occur.

DISA Rule

SV-99313r1_rule

Vulnerability Number

V-88663

Group Title

SRG-OS-000329-GPOS-00128

Rule Version

VROM-SL-001010

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Edit "/etc/pam.d/common-auth" file and add the following line:

auth required pam_tally2.so deny=3 onerr=fail even_deny_root unlock_time=86400 root_unlock_time=300

Edit "/etc/pam.d/common-account" file and add the following line:

account required pam_tally2.so

Check Contents

Check the "pam_tally2" configuration:

# more /etc/pam.d/common-auth

Confirm the following line is configured:

auth required pam_tally2.so deny=3 onerr=fail even_deny_root unlock_ti
me=86400 root_unlock_time=300

# more /etc/pam.d/common-account

Confirm the following line is configured:

account required pam_tally2.so

If no such lines are found, this is a finding.

Vulnerability Number

V-88663

Documentable

False

Rule Version

VROM-SL-001010

Severity Override Guidance

Check the "pam_tally2" configuration:

# more /etc/pam.d/common-auth

Confirm the following line is configured:

auth required pam_tally2.so deny=3 onerr=fail even_deny_root unlock_ti
me=86400 root_unlock_time=300

# more /etc/pam.d/common-account

Confirm the following line is configured:

account required pam_tally2.so

If no such lines are found, this is a finding.

Check Content Reference

M

Target Key

3461

Comments