ESXi : set-account-auto-unlock-time

Information

Set the time after which a locked account is automatically unlocked.
Multiple account login failures for the same account could possibly be a threat vector trying to brute force the system or cause denial of service. Such attempts to brute force the system should be limited by locking out the account after reaching a threshold.

In case, you would want to auto unlock the account, i.e. unlock the account without administrative action, set the time for which the account remains locked. Setting a high duration for which account remains locked would deter and serverly slow down the brute force method of logging in.

http://pubs.vmware.com/vsphere-60/topic/com.vmware.vsphere.security.doc/GUID-DC96FFDB-F5F2-43EC-8C73-05ACDAE6BE43.html

Solution

From the vSphere Web Client select the host, click "Manage" -> "Settings" -> "System" -> "Advanced Sytem Settings". Enter "Security.AccountUnlockTime" in the filter. Click edit and set the value for this parameter to 900.

See Also

https://www.vmware.com/content/dam/digitalmarketing/vmware/en/files/xls/vSphere_6_0_Hardening_Guide_GA_15_Jun_2015.xls

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7b.

Plugin: VMware

Control ID: 8c9cb6920bb87dcb94e38f2b5d233b47eb6e6721fb3e828a8e9c2494848ed1be