Download as txt, pdf, or txt
Download as txt, pdf, or txt
You are on page 1of 1

Lock the account after 3 failed logins.

in case of RHEL6 you need to use password-auth instead of system-auth


vi /etc/pam.d/system-auth
Ajouter la ligne suivante avant la ligne auth
auth
me=1800

required

sufficient

pam_unix.so

pam_tally2.so file=/var/log/tallylog deny=5 unlock_ti

puis sur la section account :


account

required

pam_tally2.so

password
5

requisite

pam_cracklib.so try_first_pass retry=5 minlen=8 difok=

Now, verify or check the counter that user attempts with the following command.
Verifier le compteur de nombre de temptative :
# pam_tally2 --user=
Login
Failures Latest
failure
From
5
04/22/13 21:22:37
172.16.16.52
# Remettre zero le compteur et activer l'accs
pam_tally2 --user= --reset
# Verifier le compteur si remis zero ou encore desactiv
# pam_tally2 --user=tecmint
Login
Failures Latest
0
vi /etc/ssh/sshd_config
set MaxAuthTries 5
service sshd restart

failure

From

You might also like