3.2.5 /etc/security/login.cfg - logintimeout

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Defines the number of seconds during which the password must be typed at login.

In setting the logintimeout attribute, a password must be entered within a specified time period.

Solution

In /etc/security/login.cfg, set the usw stanza logintimeout attribute to 30 or less-

chsec -f /etc/security/login.cfg -s usw -a logintimeout=30

This means that a user will have 30 seconds, from prompting, in which to type in their password.

See Also

https://workbench.cisecurity.org/files/528