Re: Account Lockout in Solaris 8

"Glenn M. Brunette, Jr." <[email protected]>
Newsgroups gmane.comp.security.sun
Message-ID <[email protected]>
Kenneth,

This capability does not exist natively on the Solaris 8 OS.  If you
need this capabilitity, it can be added through the use of PAM and
possibly some secondary functionality.  Note that depending on the
naming service that you use and your expectations of whether this 
lockout will be per-system or network wide, there are some 
significant issues/tradeoffs that would need to be discussed.

Also, per Kevin's e-mail, there are also a few DOS possibilities 
that exist using this method - although there are also some ways
in which those risks can be mitigated to some degree.

SunPS has built and delivered modules that perform this functionality
for a number of users.  If you are interested in something like this
please let me know.

Regards,
g

---
Glenn M. Brunette, Jr.
Principal Engineer, Chief Security Architect
Sun Professional Services, United States CTO
Sun Microsystems, Inc.


Kevin L Prigge wrote:
> 
> On Tue, Oct 14, 2003 at 04:09:38PM -0000, Kenneth Denski wrote:
> >
> >
> > Does anyone know if it is possible to implement account lockouts in Sun Solaris 8? I want to set it so that after 3 bad login attempts, the user is locked out and must be reset by the Admin.
> >
> > Is there any way to do this?
> 
> Not with stock Solaris 8, AFAIK.   I'm guessing you've been tasked
> with implementing this based on a requirement from your Audit area.
> 
> Make sure they know that there are real DOS possibilities with a
> scheme such as this, and just because this functionality was available
> on IBM mainframes, it doesn't make it a good or useful idea.
> 
> --
> Kevin Prigge, SCNA            #
> Internet Services             #
> University of Minnesota       #
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.