1.403 OL09-00-003023

Information

OL 9 must ensure account lockouts persist.

GROUP ID: V-271842
RULE ID: SV-271842r1092238

Having lockouts persist across reboots ensures that account is only unlocked by an administrator. If the lockouts did not persist across reboots, an attacker could simply reboot the system to continue brute force attacks against the accounts on the system.

Solution

Configure OL 9 maintain the contents of the faillock directory after a reboot.

Add/modify the "/etc/security/faillock.conf" file to match the following line:

dir = /var/log/faillock

See Also

https://workbench.cisecurity.org/benchmarks/27024