Advertisement
Guest User

Untitled

a guest
Jul 20th, 2016
74
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.44 KB | None | 0 0
  1. auth required /lib/security/$ISA/pam_tally.so no_magic_root
  2. account required /lib/security/$ISA/pam_tally.so deny=5 reset no_magic_root
  3.  
  4. /etc/pam.d/system-auth
  5. /etc/pam.d/login
  6. /etc/pam.d/sshd
  7.  
  8. auth required pam_tally.so no_magic_root
  9. account required pam_tally.so deny=5 reset no_magic_root
  10.  
  11. /etc/pam.d/login
  12. /etc/pam.d/sshd
  13.  
  14. auth required pam_tally.so deny=5 onerr=fail per_user no_lock_time
  15.  
  16. /etc/pam.d/common-auth
  17.  
  18. account required pam_tally.so
  19.  
  20. /etc/pam.d/common-account
  21.  
  22. /sbin/pam_tally --user USERNAME --reset
  23.  
  24. auth required pam_tally2.so file=/var/log/tallylog deny=3 even_deny_root unlock_time=1200
  25.  
  26. account required pam_tally2.so
  27.  
  28. auth required pam_tally2.so file=/var/log/tallylog deny=3 even_deny_root unlock_time=1200 root_unlock_time=60
  29.  
  30. $ ssh me@somemachine
  31. me@somemachine's password:
  32. Permission denied, please try again.
  33. me@somemachine's password:
  34. Permission denied, please try again.
  35. me@somemachine's password:
  36. Account locked due to 4 failed logins
  37. Account locked due to 5 failed logins
  38. Last login: Mon Jun 4 21:21:06 2013 from someothermachine
  39.  
  40. $ pam_tally2 --user=me
  41. Login Failures Latest failure From
  42. me 5 06/04/13 21:21:06 someothermachine
  43.  
  44. pam_tally2 --user=me --reset
  45. Login Failures Latest failure From
  46. me 5 06/04/13 21:21:06 someothermachine
  47.  
  48. $ pam_tally2 --user=me
  49. Login Failures Latest failure From
  50. me 0
  51.  
  52. passwd -u <account_name>
  53. pam_tally2 --user <account_name> --reset
  54.  
  55. #%PAM-1.0
  56.  
  57. # auth requisite pam_nologin.so
  58.  
  59. auth required pam_env.so
  60. auth requisite pam_securetty.so
  61.  
  62. auth required pam_tally2.so onerr=fail audit file=/var/log/tallylog deny=3 magic_root
  63.  
  64. # go hard and lock everything:
  65. #auth required pam_tally2.so onerr=fail audit file=/var/log/tallylog deny=3 even_deny_root root_unlock_time=60
  66.  
  67. # auth [user_unknown=ignore success=ok ignore=ignore auth_err=die default=bad] pam_securetty.so
  68.  
  69. auth required pam_unix2.so
  70.  
  71. #auth include common-auth
  72.  
  73. # novell knowledgebase 7011883
  74. account required pam_tally2.so
  75.  
  76. account include common-account
  77.  
  78. password include common-password
  79.  
  80. session required pam_loginuid.so
  81. session include common-session
  82. session optional pam_lastlog.so nowtmp
  83. session optional pam_mail.so standard
  84. session optional pam_ck_connector.so
  85.  
  86. session required pam_limits.so
  87. session required pam_unix2.so
  88. session optional pam_umask.so
  89.  
  90. password requisite pam_pwcheck.so cracklib minlen=14 remember=24 difok=4 maxrepeat=3 ucredit=-1 lcredit=-1 dcredit=-1 ocredit=-1
  91.  
  92. password required pam_unix2.so use_authtok
  93.  
  94. auth include common-auth
  95. account include common-account
  96. password include common-password
  97. session include common-session
  98.  
  99. auth required pam_env.so
  100. auth required pam_unix2.so
  101.  
  102. # auth optional pam_faildelay.so
  103. # handled with FAIL_DELAY in /etc/login.defs
  104.  
  105. account required pam_unix2.so
  106.  
  107. auth sufficient pam_rootok.so
  108.  
  109. auth include common-auth
  110. account sufficient pam_rootok.so
  111. account include common-account
  112. password include common-password
  113. session include common-session
  114. session optional pam_xauth.so
  115.  
  116. # require users to be in wheel group in order to su to root
  117.  
  118. auth required pam_wheel.so
  119.  
  120. #auth requisite pam_nologin.so
  121.  
  122. auth required pam_env.so
  123. auth required pam_tally2.so onerr=fail audit file=/var/log/tallylog deny=3 magic_root
  124. auth required pam_unix2.so
  125. #auth include common-auth
  126.  
  127. #account requisite pam_nologin.so
  128.  
  129. # novell knowledgebase 7011883
  130. account required pam_tally2.so
  131.  
  132. account include common-account
  133. password include common-password
  134. session required pam_loginuid.so
  135. session include common-session
  136. session optional pam_lastlog.so noupdate showfailed
  137.  
  138. auth include common-auth
  139. account include common-account
  140. password include common-password
  141. session required pam_loginuid.so
  142. session include common-session
  143.  
  144. # disable root console login for gdm
  145.  
  146. auth required pam_succeed_if.so user != root audit
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement