STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 8 Security Technical Implementation Guide Version: 2 Release: 8 Benchmark Date: 01 Jul 2026:

RHEL 8 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.

DISA Rule

SV-230337r1134885_rule

Vulnerability Number

V-230337

Group Title

SRG-OS-000021-GPOS-00005

Rule Version

RHEL-08-020015

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the operating system to lock an account until released by an administrator when three unsuccessful logon attempts occur in 15 minutes.

Add/Modify the "/etc/security/faillock.conf" file to match the following line:

unlock_time = 0

Check Contents

Verify the "/etc/security/faillock.conf" file is configured to lock an account until released by an administrator after three unsuccessful logon attempts:

$ sudo grep 'unlock_time =' /etc/security/faillock.conf

unlock_time = 0

If the "unlock_time" option is not set to "0", or is missing or commented out, this is a finding.

Vulnerability Number

V-230337

Documentable

False

Rule Version

RHEL-08-020015

Severity Override Guidance

Verify the "/etc/security/faillock.conf" file is configured to lock an account until released by an administrator after three unsuccessful logon attempts:

$ sudo grep 'unlock_time =' /etc/security/faillock.conf

unlock_time = 0

If the "unlock_time" option is not set to "0", or is missing or commented out, this is a finding.

Check Content Reference

M

Target Key

2921