AOSX-09-001324 - System must enforce the limit of three consecutive invalid logon attempts by a user during a 15 minute time period.

Information

Setting a lockout expiration of 15 minutes is an effective deterrent against brute forcing that also makes allowances for legitimate mistakes by users.

Solution

To set the password policy, run the following command:

sudo pwpolicy setglobalpolicy 'maxFailedLoginAttempts=3'

See Also

http://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-9_Workstation_V1R2_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7, CAT|II, CCI|CCI-002238, CSCv6|16.7, Group-ID|V-58467, Rule-ID|SV-72897r1_rule, STIG-ID|AOSX-09-001324

Plugin: Unix

Control ID: b63668ca2d4d6d8e8b7427b9ea3abeb0ec4cfc5a5896db3e61fdb480167685fe