SV-274154r1120450_rule
V-274154
SRG-OS-000329-GPOS-00128
AZLX-23-002455
CAT II
10
Configure Amazon Linux 2023 to lock an account when three unsuccessful logon attempts occur.
Add/modify the "/etc/security/faillock.conf" file to match the following line:
deny = 3
Verify Amazon Linux 2023 is configured to lock an account after three unsuccessful logon attempts with the command:
$ grep 'deny =' /etc/security/faillock.conf
deny = 3
If the "deny" option is not set to "3" or less (but not "0"), is missing or commented out, this is a finding.
V-274154
False
AZLX-23-002455
Verify Amazon Linux 2023 is configured to lock an account after three unsuccessful logon attempts with the command:
$ grep 'deny =' /etc/security/faillock.conf
deny = 3
If the "deny" option is not set to "3" or less (but not "0"), is missing or commented out, this is a finding.
M
5700