1.85 SOL-11.1-040140

Information

The system must disable accounts after three consecutive unsuccessful login attempts.

GROUP ID: V-216334
RULE ID: SV-216334r958388

Allowing continued access to accounts on the system exposes them to brute-force password-guessing attacks.

Solution

The root role is required.

# pfedit /etc/default/login

Change the line:

#RETRIES=5

to read

RETRIES=3 pfedit /etc/security/policy.conf

Change the line containing

#LOCK_AFTER_RETRIES

to read:

LOCK_AFTER_RETRIES=YES

If a user has lock_after_retries set to "no", update the user's attributes using the command:

# usermod -K lock_after_retries=yes [username]

See Also

https://workbench.cisecurity.org/benchmarks/23765