Skip to content

Ensure the Logon Failure Delay is Set Correctly in login.defs

An XCCDF Rule

Description

To ensure the logon failure delay controlled by /etc/login.defs is set properly, add or correct the FAIL_DELAY setting in /etc/login.defs to read as follows:

FAIL_DELAY 

Rationale

Increasing the time between a failed authentication attempt and re-prompting to enter credentials helps to slow a single-threaded brute force attack.

ID
xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay
Severity
Medium
References
Updated