OSX00045 - Account lockout duration

Information

The amount of time that a user's account is locked after multiple failed login attempts.

Solution

Open a terminal session and use the following command to set the value for Account lockout duration- sudo pwpolicy -n -setglobalpolicy 'minutesUntilFailedLoginReset=0'.

Note- For non-managed system, use the command- pwpolicy -n /Local/Default -setglobalpolicy 'minutesUntilFailedLoginReset=0'.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx10.5_v1r2_stig_20110729.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7, CAT|II, Rule-ID|SV-31284r1_rule, STIG-ID|OSX00045, Vuln-ID|V-25240

Plugin: Unix

Control ID: 48435d1a0f27e607bdc2eca5bf3d75b7b767c11cc3ede591b252040f382f8d89