Account Lockout on Redhat

 
Thread Tools Search this Thread
Operating Systems Linux Red Hat Account Lockout on Redhat
# 1  
Old 01-18-2012
Account Lockout on Redhat

On a redhat linux 4 server, how to find if there is an account lockout duration is set. Is it configured under pam or /etc/shadow? what entries I need to find out? Is it pam_time.so module?

I desperately need an answer because on one of the servers, no one was able to login through any account (not from ssh or through console), and repeated reboots didn't help either and just when everybody was about to give up, suddenly everyone was able to log in.

What could it be, please recommend.

Regards
# 2  
Old 01-19-2012
and check your
Code:
 /etc/pam.d/system-auth

settings

alternatively to find out what went wrong, check your /var/log/faillog
# 3  
Old 01-19-2012
well that is what my /etc/pam,d/syste,-auth file looks ike, does it indicate something set incorrectly?

PHP Code:
#%PAM-1.0
# This file is auto-generated.
# User changes will be destroyed the next time authconfig is run.
auth        required      /lib/security/$ISA/pam_env.so
auth        sufficient    
/lib/security/$ISA/pam_unix.so likeauth nullok
auth        sufficient    
/lib/security/$ISA/pam_ldap.so use_first_pass
auth        required      
/lib/security/$ISA/pam_deny.so

account     required      
/lib/security/$ISA/pam_unix.so
account     
[default=bad success=ok user_unknown=ignore service_err=ignore system_err=ignore] /lib/security/$ISA/pam_ldap.so
account     sufficient    
/lib/security/$ISA/pam_succeed_if.so uid 100 quiet
account     required      
/lib/security/$ISA/pam_permit.so

password    requisite     
/lib/security/$ISA/pam_cracklib.so retry=3
password    sufficient    
/lib/security/$ISA/pam_unix.so nullok use_authtok md5 shadow
password    sufficient    
/lib/security/$ISA/pam_ldap.so use_authtok
password    required      
/lib/security/$ISA/pam_deny.so

session     required      
/lib/security/$ISA/pam_limits.so
session     required      
/lib/security/$ISA/pam_unix.so
session     optional      
/lib/security/$ISA/pam_ldap.so 
# 4  
Old 01-19-2012
In what way were they unable to login? Were you getting connection timed out or passwords refused, or what?
# 5  
Old 01-21-2012
/var/log/messages and/or /var/log/secure should show you why the logins were denied.
Login or Register to Ask a Question

Previous Thread | Next Thread

9 More Discussions You Might Find Interesting

1. Red Hat

RHEL4.8 no notification on PAM lockout

Good day. I have setup hardening the password (test system so far) prior to doing any work on production. Here is what I have set. Snippet from /etc/pam.d/system-auth auth required /lib/security/$ISA/pam_env.so auth required /lib/security/$ISA/pam_tally.so... (3 Replies)
Discussion started by: smurphy_it
3 Replies

2. Solaris

Secman lockout

Greetings, I work with a Solaris Sun Server V240 system (GCCS) and have run into a problem where I can't seem to unlock my SECMAN account at the NON-GLOBAL level. I have access to all global accounts to include sysadmin and secman. I have access to the non-global sysadmin account and root... (4 Replies)
Discussion started by: TLAMGUY
4 Replies

3. Red Hat

Account lockout

having account lockout issues with an RHEL 5 server. My users are getting locked out for 10 minutes after one failed login attempt even though /etc/pam.d/sshd is configured for 5 failed attempts: auth include system-auth auth required pam_tally2.so deny=5 onerr=fail... (1 Reply)
Discussion started by: nerdalert
1 Replies

4. UNIX and Linux Applications

Account lockout using Openldap

What is the best way to implement account lockout in openldap? I have an openldap server with Ubuntu desktop client connecting to it for authentication. I want he accounts to locked out after say 5 failed authentication attempts I have enabled ppolicy layout in slapd.conf. overlay ppolicy... (0 Replies)
Discussion started by: nitin09
0 Replies

5. Red Hat

Account lockout policy

Hi all; I m using Red Hat Enterprise Linux Server release 5.1 (Tikanga) and I'm trying to setup password lockout policy so that a user account locks out after 3 failed attempts. Here are the entires of my /etc/pam.d/system-auth #%PAM-1.0 # This file is auto-generated. # User changes... (1 Reply)
Discussion started by: maverick_here
1 Replies

6. AIX

lockout su for 1 user

I want to know if there is any easy way of stopping 1 user from using su? perferabily any su but I can make do with not allow him to su to root but allow other user to su to root. (3 Replies)
Discussion started by: daveisme
3 Replies

7. AIX

user lockout...

Hi, We are using 4.3.3.0 and I would like to make a global change to the "number of failed logins before user account is locked" Any ideas, other than using SMIT one user at a time.... ??? Thanks... Craig. (2 Replies)
Discussion started by: stumpy
2 Replies

8. UNIX for Dummies Questions & Answers

root lockout

Hi, I am extremely new to UNIX and was recently promoted to administer the system for a small company. Anyhow, the time came for passwords to change, and I made the huge mistake of entering in the command (as root) passwd -l After logging out (oblivious to what would happen next), the root... (4 Replies)
Discussion started by: newbieadmin
4 Replies

9. UNIX for Dummies Questions & Answers

Lockout Users

I am using AIx 4.3.3 and was wondering what the command was to keep users from logging in. I want to be able to do maintenance and keep the users out. Can anyone help? (7 Replies)
Discussion started by: cgillett
7 Replies
Login or Register to Ask a Question