Changeset 196
- Timestamp:
- 06/07/08 08:56:00
(6 months ago)
- Author:
- slawrence
- Message:
Update stigs to match pam conf changes.
-
Files:
-
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
| r154 |
r196 |
|
| 10 | 10 | cat <<-EOF > /etc/pam.d/system-auth |
|---|
| 11 | 11 | #%PAM-1.0 |
|---|
| 12 | | auth required pam_tally.so deny=3 onerr=fail unlock_time=900 quiet |
|---|
| 13 | | |
|---|
| | 12 | # This file is auto-generated. |
|---|
| | 13 | # User changes will be destroyed the next time authconfig is run. |
|---|
| | 14 | #5 login attempts within 30 seconds. Locked out for 60 seconds if fail |
|---|
| | 15 | auth required pam_tally.so deny=3 onerr=fail unlock_time=900 quiet |
|---|
| 14 | 16 | auth required pam_env.so |
|---|
| 15 | | auth required pam_unix.so nullok try_first_pass audit |
|---|
| | 17 | auth sufficient pam_unix.so nullok try_first_pass audit |
|---|
| | 18 | auth requisite pam_succeed_if.so uid >= 500 quiet |
|---|
| | 19 | auth required pam_deny.so |
|---|
| 16 | 20 | |
|---|
| 17 | 21 | account required pam_unix.so |
|---|
| 18 | | account required pam_tally.so |
|---|
| | 22 | account required pam_tally.so |
|---|
| | 23 | account sufficient pam_succeed_if.so uid < 500 quiet |
|---|
| | 24 | account required pam_permit.so |
|---|
| | 25 | |
|---|
| 19 | 26 | password required pam_cracklib.so try_first_pass retry=3 minlen=12 difok=3 dcredit=-2 ucredit=-2 ocredit=-2 lcredit=-2 |
|---|
| 20 | | password required pam_unix.so md5 shadow nullok try_first_pass use_authtok remember=12 |
|---|
| | 27 | password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok remember=12 |
|---|
| | 28 | password required pam_deny.so |
|---|
| 21 | 29 | |
|---|
| 22 | 30 | session optional pam_keyinit.so revoke |
|---|
| 23 | 31 | session required pam_limits.so |
|---|
| | 32 | session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid |
|---|
| 24 | 33 | session required pam_unix.so |
|---|
| 25 | 34 | EOF |
|---|
Download in other formats:
* Generating other formats may take time.