How to lock a user after X unsuccessful attempts

Remi Ferrand <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Organization CC-IN2P3
Message-ID <[email protected]>
Hi,

I'm using Heimdal kerberos  and I would like to lock my users accounts
for a predefined amount of time (e.g 30 minutes) after they made X
unsuccessful identification attempts, as it was possible with the KAS
server of OpenAFS (http://docs.openafs.org/AdminGuide/ch13s06.html).
I know that MIT Kerberos has implemented the *lockout* functionnality
since 1.8, what about Heimdal ?

What's the best solution to reach that goal ?
Is logs parsing the only way to do this ?

Thanks in advance

Cheers

R.

-- 

Remi Ferrand             | Institut National de Physique Nucleaire
Tel. +33(0)4.78.93.08.80 |     et de Physique des Particules
Fax. +33(0)4.72.69.41.70 | Centre de Calcul - http://cc.in2p3.fr/
smime.p7s (application/pkcs7-signature, 4 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.