GEN000480 - The delay between login prompts following a failed login attempt must be at least 4 seconds.

Information

Enforcing a delay between successive failed login attempts increases protection against automated password guessing attacks.

Solution

Use vi or the chsec command to change the login delay time period.
#chsec -f /etc/security/login.cfg -s default -a logindelay=4
OR
# vi /etc/security/login.cfg
Add logindelay = 4 to the default stanza.

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7, CAT|II, CCI|CCI-000043, Rule-ID|SV-38839r1_rule, STIG-ID|GEN000480, Vuln-ID|V-768

Plugin: Unix

Control ID: b385c19fd2f78ce57122bee4c4b353988dfe5af31232a2396393a858f9440ce6