<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: account disabled message on auth failure in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/account-disabled-message-on-auth-failure/m-p/4295458#M34284</link>
    <description>its not happening; Any other criteria along with the /sbin/nologin?&lt;BR /&gt;&lt;BR /&gt;# faillog -u ftphrgl&lt;BR /&gt;Username   Failures  Maximum  Latest&lt;BR /&gt;ftphrgl           6        0  Tue Oct 28 20:01:43 -0400 2008 on 147.154.162&lt;BR /&gt;&lt;BR /&gt;[root@adela161p pam.d]# grep account system-auth&lt;BR /&gt;account     required      /lib/security//pam_unix.so&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Tue, 28 Oct 2008 23:45:18 GMT</pubDate>
    <dc:creator>skt_skt</dc:creator>
    <dc:date>2008-10-28T23:45:18Z</dc:date>
    <item>
      <title>account disabled message on auth failure</title>
      <link>https://community.hpe.com/t5/operating-system-linux/account-disabled-message-on-auth-failure/m-p/4295456#M34282</link>
      <description>RHEL AS 2.1/3/4/5&lt;BR /&gt;&lt;BR /&gt;I have noticed that the LINUX user accounts are not returing an error message  "account is disabled;contact your system administrator"  unlike HP-UX.&lt;BR /&gt;&lt;BR /&gt;is there a way to get a similar message in Linux? We use pam authentication</description>
      <pubDate>Tue, 28 Oct 2008 13:35:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/account-disabled-message-on-auth-failure/m-p/4295456#M34282</guid>
      <dc:creator>skt_skt</dc:creator>
      <dc:date>2008-10-28T13:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: account disabled message on auth failure</title>
      <link>https://community.hpe.com/t5/operating-system-linux/account-disabled-message-on-auth-failure/m-p/4295457#M34283</link>
      <description>Â¿Under which circunstances do you want to get a similar message? For example, if she shell is /sbin/nologin you will get a similar message.</description>
      <pubDate>Tue, 28 Oct 2008 17:19:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/account-disabled-message-on-auth-failure/m-p/4295457#M34283</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2008-10-28T17:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: account disabled message on auth failure</title>
      <link>https://community.hpe.com/t5/operating-system-linux/account-disabled-message-on-auth-failure/m-p/4295458#M34284</link>
      <description>its not happening; Any other criteria along with the /sbin/nologin?&lt;BR /&gt;&lt;BR /&gt;# faillog -u ftphrgl&lt;BR /&gt;Username   Failures  Maximum  Latest&lt;BR /&gt;ftphrgl           6        0  Tue Oct 28 20:01:43 -0400 2008 on 147.154.162&lt;BR /&gt;&lt;BR /&gt;[root@adela161p pam.d]# grep account system-auth&lt;BR /&gt;account     required      /lib/security//pam_unix.so&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 28 Oct 2008 23:45:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/account-disabled-message-on-auth-failure/m-p/4295458#M34284</guid>
      <dc:creator>skt_skt</dc:creator>
      <dc:date>2008-10-28T23:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: account disabled message on auth failure</title>
      <link>https://community.hpe.com/t5/operating-system-linux/account-disabled-message-on-auth-failure/m-p/4295459#M34285</link>
      <description>The "account is disabled" message will reveal to a potential intruder that the account *exists*, which can be an unacceptable information leak in high-security environments.&lt;BR /&gt;&lt;BR /&gt;Ideally, the intruder should not be able to tell these three cases apart:&lt;BR /&gt;a) the account does not exist&lt;BR /&gt;b) the account does exist, but it is locked; no password will allow entry&lt;BR /&gt;c) the account exists and is not locked, but the intruder specified a wrong password.&lt;BR /&gt;&lt;BR /&gt;The information to identify these cases should certainly be available to the sysadmin, so the correct place for it is the secure system log (/var/log/secure or /var/log/auth.log in most Linux distributions).&lt;BR /&gt;&lt;BR /&gt;A secure way would be to add a short reminder to the end of /etc/issue or the equivalent pre-login message ("banner" in OpenSSH-style sshd configuration). Something generic like "If you have problems logging in, contact..." &lt;BR /&gt;&lt;BR /&gt;Of course, the accounts helpdesk, sysadmin or whoever handles the login problems should be required to always identify the users in some reliable way before unlocking any accounts. &lt;BR /&gt;&lt;BR /&gt;MK</description>
      <pubDate>Wed, 29 Oct 2008 10:53:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/account-disabled-message-on-auth-failure/m-p/4295459#M34285</guid>
      <dc:creator>Matti_Kurkela</dc:creator>
      <dc:date>2008-10-29T10:53:25Z</dc:date>
    </item>
  </channel>
</rss>

