The system must disable accounts after three consecutive unsuccessful login attempts.

From HP-UX 11.31 Security Technical Implementation Guide

Part of GEN000460

Associated with IA controls: ECLO-1, ECLO-2

Associated with: CCI-000044

SV-38445r1_rule The system must disable accounts after three consecutive unsuccessful login attempts.

Vulnerability discussion

Disabling accounts after a limited number of unsuccessful login attempts improves protection against password guessing attacks.

Check content

Fix text

SMH is installed with defaults. Modify the env variables and tag values using the HP-SMH. Locate and set the number of login tries to 3.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer