1.285 RHEL-09-411105

Information

RHEL 9 must ensure account lockouts persist.

GROUP ID: V-258060
RULE ID: SV-258060r1045150

Having lockouts persist across reboots ensures that account is only unlocked by an administrator. If the lockouts did not persist across reboots, an attacker could simply reboot the system to continue brute force attacks against the accounts on the system.

Solution

Configure RHEL 9 maintain the contents of the faillock directory after a reboot.

Add/modify the "/etc/security/faillock.conf" file to match the following line:

dir = /var/log/faillock

See Also

https://workbench.cisecurity.org/benchmarks/22008

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7a., CAT|II, CCI|CCI-000044, Rule-ID|SV-258060r1045150_rule, STIG-ID|RHEL-09-411105, Vuln-ID|V-258060

Plugin: Unix

Control ID: 80080c23c25af70840feeee9f143ad045b0c6e98a076371f4a764692cbac22f7