- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: AUTH_MAXTRIES question
Operating System - HP-UX
1753628
Members
5375
Online
108797
Solutions
Forums
Categories
Company
Local Language
юдл
back
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
юдл
back
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Blogs
Information
Community
Resources
Community Language
Language
Forums
Blogs
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-09-2010 01:57 PM
тАО09-09-2010 01:57 PM
AUTH_MAXTRIES question
I have a concern that setting AUTH_MAXTRIES to a non-zero value will result in an escalation of user calls due to locked account. (There's also a worry that implementing this could allow a type of denial of service attack.)
What I would like to do is satisfy the spirit of the configuration setting, while not requiring SysAdmin intervention. To do that, I'd like for locked accounts to be automatically released after a relatively brief period of time (enough to deter an attacker, but not enough to bring work to a halt). However, it doesn't appear that the userdbget command provides the type of information I'd need to implement a cron job to unlock lockouts.
Has anybody scripted a method for implementing this? Do I need to delve into the /var/adm/userdb entries? Thank you.
What I would like to do is satisfy the spirit of the configuration setting, while not requiring SysAdmin intervention. To do that, I'd like for locked accounts to be automatically released after a relatively brief period of time (enough to deter an attacker, but not enough to bring work to a halt). However, it doesn't appear that the userdbget command provides the type of information I'd need to implement a cron job to unlock lockouts.
Has anybody scripted a method for implementing this? Do I need to delve into the /var/adm/userdb entries? Thank you.
2 REPLIES 2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-13-2010 09:10 AM
тАО09-13-2010 09:10 AM
Re: AUTH_MAXTRIES question
On a related note, HP was kind enough to show me how to get AUTH_MAXTRIES to work for secure shell (ssh) without removing "UsePAM yes" from the sshd_config file. You need to add "ignore_unknown" to the "sshd auth required" entry for libpam_ldap.so.1 entry in /etc/pam.conf. This is documented in pam_ldap(5).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-13-2010 10:31 AM
тАО09-13-2010 10:31 AM
Re: AUTH_MAXTRIES question
Never mind, I figured it out. Run:
/usr/sbin/userdbget -i -a auth_failures
then look for accounts where the value returned in "auth_failures=value" exceed the AUTH_MAXTRIES value. Unlock an account with:
/usr/sbin/userdbset -d -u account
/usr/sbin/userdbget -i -a auth_failures
then look for accounts where the value returned in "auth_failures=value" exceed the AUTH_MAXTRIES value. Unlock an account with:
/usr/sbin/userdbset -d -u account
- Tags:
- userdbget
The opinions expressed above are the personal opinions of the authors, not of Hewlett Packard Enterprise. By using this site, you accept the Terms of Use and Rules of Participation.
News and Events
Support
© Copyright 2024 Hewlett Packard Enterprise Development LP