Results 1 to 10 of 15

Thread: [SOLVED] Lock account after failed password attempts

Hybrid View

  1. #1
    Join Date
    Apr 2008
    Location
    Kansas City
    Beans
    509

    [SOLVED] Lock account after failed password attempts

    Anyone can attempt to login to my computer Ubuntu machines as many times as they want... ewww... Ideally, I'd like to limit users to three login attempts and then lock out their account until an administrator unlocks it or the server is rebooted.

    Google appears to suggest it's possible, but all the information I find seems to suggest editing a /etc/pam.d/system_auth file. I have the /etc/pam.d folder with files in it, but no system_auth file.

    Can someone list out the steps necessary to accomplish this in Ubuntu?

  2. #2
    Join Date
    Oct 2007
    Beans
    197

    Re: Lock account after failed password attempts

    If it is ssh access there is denyhosts and you can configure it to only allow 3 times before there ip is placed into hosts.deny and denied access until there ip changes or the administrator edits the denyhosts logs and unblocks them.

  3. #3
    Join Date
    Apr 2008
    Location
    Kansas City
    Beans
    509

    Re: Lock account after failed password attempts

    No, I meant to say when someone is physically sitting in front of a terminal and logging into Ubuntu gnome desktop... I want to kill their account if they keep guessing at the password.

  4. #4
    Join Date
    Oct 2007
    Beans
    197

    Re: Lock account after failed password attempts

    With some help with google. This may be what you are after ?
    http://www.cyberciti.biz/tips/lock-u...-attempts.html

  5. #5
    Join Date
    Apr 2008
    Location
    Kansas City
    Beans
    509

    Re: Lock account after failed password attempts

    Yeah, that's what I was talking about in the orignal post... All the google answers seem to say it can be done, by editing this system_auth file... but on Ubuntu version of linux there is no system_auth file in the /etc/pam.d folder.

  6. #6
    Join Date
    Apr 2008
    Location
    Kansas City
    Beans
    509

    Re: Lock account after failed password attempts

    Ah, got it working...

    In Ubuntu, the file is named:
    /etc/pam.d/common-auth
    instead of:
    /etc/pam.d/system-auth
    I had guessed this earlier... but it failed to work as a substitute... this is because I followed the directions and appended this code to that file.
    auth required pam_tally.so onerr=fail deny=5 unlock_time=21600
    however, that isn't what you need to do to make it work... that code must appear BEFORE the other codes in the file... so don't append it to the end, instead put it at the beginning, and now it works!

    Thanks for holding my hand, I couldn't find a clear answer on this anywhere.

  7. #7
    Join Date
    Jul 2007
    Location
    Magic City of the Plains
    Beans
    Hidden!
    Distro
    Xubuntu 17.10 Artful Aardvark

    Re: [SOLVED] Lock account after failed password attempts

    Old thread closed. Instead of bumping old threads, please start a new one if you have a question or problem.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •