<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Linux user account in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/linux-user-account/m-p/5753659#M53832</link>
    <description>&lt;P&gt;Which version of RHEL? ("cat /etc/redhat-release" please)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depending on the version, the PAM module you'll need is either pam_tally.so or pam_tally2.so.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You must add the tally module to both "auth" and "account" phases in the PAM configuration: the "auth" phase increments the user's login count and rejects the login if the count is too high, the "account" phase resets the counter when a login is successful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ordering of PAM configuration entries is important and non-trivial. The RedHat Knowledge Base has several articles on configuring pam_tally:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recommended configuration with pam_tally2:&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="https://access.redhat.com/knowledge/solutions/37687"&gt;https://access.redhat.com/knowledge/solutions/37687&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With some versions (using the older pam_tally) the count may be wrong when using SSH (my guess: an attempt to use SSH key authentication may count as one login attempt?):&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="https://access.redhat.com/knowledge/solutions/67401"&gt;https://access.redhat.com/knowledge/solutions/67401&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the number of failed logins causes the login to be rejected, the message in the system logs may not be obvious, as with sudo:&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="https://access.redhat.com/knowledge/solutions/43006"&gt;https://access.redhat.com/knowledge/solutions/43006&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Aug 2012 14:38:24 GMT</pubDate>
    <dc:creator>Matti_Kurkela</dc:creator>
    <dc:date>2012-08-06T14:38:24Z</dc:date>
    <item>
      <title>Linux user account</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-user-account/m-p/5753277#M53831</link>
      <description>&lt;P&gt;hi friends,&lt;/P&gt;&lt;P&gt;Need help in locking an Linux user account after three failed logins. The server is RHEL, and i tried the PAM settings, but doesn't seem to work with RHEL. The Linux accounts are configured to login using ssh authentication.&lt;/P&gt;&lt;P&gt;If somebody can help me on this, I would really appreciate it.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2012 10:12:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-user-account/m-p/5753277#M53831</guid>
      <dc:creator>jitjose</dc:creator>
      <dc:date>2012-08-06T10:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Linux user account</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-user-account/m-p/5753659#M53832</link>
      <description>&lt;P&gt;Which version of RHEL? ("cat /etc/redhat-release" please)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depending on the version, the PAM module you'll need is either pam_tally.so or pam_tally2.so.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You must add the tally module to both "auth" and "account" phases in the PAM configuration: the "auth" phase increments the user's login count and rejects the login if the count is too high, the "account" phase resets the counter when a login is successful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ordering of PAM configuration entries is important and non-trivial. The RedHat Knowledge Base has several articles on configuring pam_tally:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recommended configuration with pam_tally2:&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="https://access.redhat.com/knowledge/solutions/37687"&gt;https://access.redhat.com/knowledge/solutions/37687&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With some versions (using the older pam_tally) the count may be wrong when using SSH (my guess: an attempt to use SSH key authentication may count as one login attempt?):&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="https://access.redhat.com/knowledge/solutions/67401"&gt;https://access.redhat.com/knowledge/solutions/67401&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the number of failed logins causes the login to be rejected, the message in the system logs may not be obvious, as with sudo:&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="https://access.redhat.com/knowledge/solutions/43006"&gt;https://access.redhat.com/knowledge/solutions/43006&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2012 14:38:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-user-account/m-p/5753659#M53832</guid>
      <dc:creator>Matti_Kurkela</dc:creator>
      <dc:date>2012-08-06T14:38:24Z</dc:date>
    </item>
  </channel>
</rss>

