SOL-11.1-040140 - The system must disable accounts after three consecutive unsuccessful login attempts.

Information

Allowing continued access to accounts on the system exposes them to brute-force password-guessing attacks.

Solution

The root role is required.

# pfedit /etc/default/login

Change the line:

#RETRIES=5

to read

RETRIES=3

pfedit /etc/security/policy.conf

Change the line containing

#LOCK_AFTER_RETRIES

to read:

LOCK_AFTER_RETRIES=YES

If a user has lock_after_retries set to "no", update the user's attributes using the command:

# usermod -K lock_after_retries=yes [username]

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_x86_V3R6_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7a., CAT|II, CCI|CCI-000044, Rule-ID|SV-216099r958388_rule, STIG-ID|SOL-11.1-040140, STIG-Legacy|SV-61117, STIG-Legacy|V-48245, Vuln-ID|V-216099

Plugin: Unix

Control ID: 11a838ce76f30b1ac1d8e9efd3ea7add9d715d259cc995b1225dd8b0012c4cd9