Skip to content

AlmaLinux OS 9 must automatically lock an account when three unsuccessful logon attempts occur.

An XCCDF Rule

Description

By limiting the number of failed logon attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-force attacks, is reduced. Limits are imposed by locking the account.

ID
SV-269147r1050029_rule
Version
ALMA-09-007500
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure AlmaLinux OS 9 to lock an account when three unsuccessful logon attempts occur using pam_faillock.

First, enable the feature using the following command:

$ authselect enable-feature with-faillock