Lock out a Solaris user after x failed attempts

Hello all,

I would like to lock out a Solaris 8 user after 'x' failed attempts. I know that this is not a built in function but have read it could be done using PAM? Is this the right route and if so are there any 'How to' documents to set this up.

Thanks in advance.
cicssjwAsked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
TintinConnect With a Mentor Commented:
yuhz.

There was no mention of Trusted Solaris and not many people run it anyway.

The answer is to install PAM_login_limit from http://www.comsmiths.com.au/pam/pam_1.04.html

0
 
yuzhCommented:
Here's what you need to do:

1. Edit /etc/default/login file to add, allow 3 login attempt

#
# Set the number of retries  for  logging in, the default is 5.
#
RETRIES=3

2. create a longinlog file
   touch /var/adm/loginlog
   chmod 600 /var/adm/loginlog
   the file permission looks like:
   -rw-------   1 root     sys         4757 Jun 14 02:23 /var/adm/loginlog

  that's it.

  PS: you can write a script to monitor the /var/adm/loginlog  to mail the failed
        login infor to you.



0
 
cicssjwAuthor Commented:
Hi yuzh,

I have already done what you have suggested, but this allows the user to start-up another telnet session and try again. We have an audit requirement to actually lock the user out after 'x' failed attempts. The only other thought I had is to write a script to monitor the loginlog and then lock the user out.

I didn't want to reinvent the wheel as this must have been done many times before.

Thanks.
0
 
yuzhCommented:
If you want to lock the user's account, have a look at the following
Sun doc to learn how:

http://docs.sun.com/db/doc/805-8120-10/6j7kqn65k?a=view
0
 
cicssjwAuthor Commented:
We are not running Trusted Solairs. Thanks for all the valuable comments.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.