From AIX 6.1 SECURITY TECHNICAL IMPLEMENTATION GUIDE
Part of GEN000460
Associated with IA controls: ECLO-1, ECLO-2
Associated with: CCI-000044
Disabling accounts after a limited number of unsuccessful login attempts improves protection against password guessing attacks.
# /usr/sbin/lsuser -a loginretries ALL | more Check all active accounts on the system for the maximum number of tries before the system will lock the account. If a user has values set to 0 or greater then 3, this is a finding.
Use the chsec command to configure the number of unsuccessful logins resulting in account lockout.  
# chsec -f /etc/security/user -s default -a loginretries=3 
# chsec -f /etc/security/user -s 
	Lavender hyperlinks in small type off to the right (of CSS
	class id, if you view the page source) point to
	globally unique URIs for each document and item. Copy the
	link location and paste anywhere you need to talk
	unambiguously about these things.
	
      
	You can obtain data about documents and items in other
	formats. Simply provide an HTTP header Accept:
	text/turtle or
	Accept: application/rdf+xml.
      
Powered by sagemincer