Information
The system must disable accounts after three consecutive unsuccessful login attempts.
GROUP ID: V-216334
RULE ID: SV-216334r958388
Allowing continued access to accounts on the system exposes them to brute-force password-guessing attacks.
Solution
The root role is required.
# pfedit /etc/default/login
Change the line:
#RETRIES=5
to read
RETRIES=3 pfedit /etc/security/policy.conf
Change the line containing
#LOCK_AFTER_RETRIES
to read:
LOCK_AFTER_RETRIES=YES
If a user has lock_after_retries set to "no", update the user's attributes using the command:
# usermod -K lock_after_retries=yes [username]