ALMA-09-008160 - AlmaLinux OS 9 must maintain an account lock until the locked account is manually released by an administrator; and not automatically after a set time.

Information

By limiting the number of failed logon attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-force attacks, is reduced. Limits are imposed by locking the account.

Solution

Configure AlmaLinux OS 9 to lock accounts until released by an administrator using pam_faillock.

First, enable the feature using the following command:

$ authselect enable-feature with-faillock

Then, add or uncomment the following line in the "/etc/security/faillock.conf" file:

unlock_time = 0

See Also

https://workbench.cisecurity.org/benchmarks/0

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7b., CAT|II, CCI|CCI-002238, Rule-ID|SV-269153r1050035_rule, STIG-ID|ALMA-09-008160, Vuln-ID|V-269153

Plugin: Unix

Control ID: 4bbe8acddcb682d02594b472f2765a7b6b4c2ee1c9224dd1a1e5a2913a3de84e