GEN000460 - The system must disable accounts after three consecutive unsuccessful login attempts.

Information

Disabling accounts after a limited number of unsuccessful login attempts improves protection against password guessing attacks.

Solution

Use the chsec command to configure the number of unsuccessful logins resulting in account lockout.

# chsec -f /etc/security/user -s default -a loginretries=3
# chsec -f /etc/security/user -s <user id> -a loginretries=3

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7a., CAT|II, CCI|CCI-000044, Group-ID|V-766, Rule-ID|SV-38671r1_rule, STIG-ID|GEN000460, Vuln-ID|V-766

Plugin: Unix

Control ID: 0987cfc7e571978e440949be9c05d005b9b7488225546b7b8771e058f654ff65