LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-03-2010, 03:06 AM   #1
Theleo
LQ Newbie
 
Registered: May 2010
Posts: 3

Rep: Reputation: 0
pam_tally2 prevent lockout


Hi my fist post,tons of info on the forum but still didn't find
a solution to my prob.

I am trying to harden a production system running rhel 5.4
My problem is with pam_tally2.I want pam_tally2 to lockout almost all users
after 3 failled attempts,i can do that easilly with deny=3.My problem
is that for some users or for a specific group i want pam_tally2 not to lock
their accounts not matter how many attempts they trie,to prevent a denial
of service attack.Any idea on how to do this,

Much appreciated

p.s seems that the per_user option is not working as expected,meaning
that even if i setup a faillog -m 0 username pam_tally2 overwrites that
every time i login with m=3 for all users,perhaps i am missing something here.
 
Old 05-09-2010, 06:34 AM   #2
Theleo
LQ Newbie
 
Registered: May 2010
Posts: 3

Original Poster
Rep: Reputation: 0
Anyone thought of something?Perhaps this cannot be done.If someone can confirm that i would be happy.
Thanks
 
Old 05-10-2010, 01:28 PM   #3
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
NB: pam_tally is a different module than pam_tally2. You can't invoke the latter and assume it will behave like the former.

Read the following documentation on your RHEL5 system:
  • /usr/share/doc/pam-0.99.6.2/txts/README.pam_tally
  • /usr/share/doc/pam-0.99.6.2/txts/README.pam_tally2
 
Old 05-10-2010, 04:23 PM   #4
frndrfoe
Member
 
Registered: Jan 2008
Distribution: RHEL, CentOS, Ubuntu
Posts: 379

Rep: Reputation: 38
Perhaps a different approach is in order, do your users reside in openldap?
The ppolicy overlay is configurable to have different rules for different users or groups of users. Using ppolicy with access.conf and Denyhosts might solve most of your problem.

This is the basic soup I start with.

http://www.openldap.org/doc/admin24/overlays.html
http://linux.die.net/man/5/access.conf
http://denyhosts.sourceforge.net/

I apologize that this does not answer your question directly. I have not seen the other thread and perhaps this has been said similarly.

Last edited by frndrfoe; 05-10-2010 at 04:29 PM.
 
Old 05-18-2010, 10:35 AM   #5
Theleo
LQ Newbie
 
Registered: May 2010
Posts: 3

Original Poster
Rep: Reputation: 0
anomie:have read the documentation still couldn't find an answer to my problem.Thanks for the reply

frndrfoe:i was hoping to avoid openldap mainly because i have no knowledge of it.Since it seems there is no other way i will wait a few more days and if no other user answers i will have a go at it.Thanks for the reply.
 
Old 05-18-2010, 11:40 AM   #6
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Maybe you missed this, then: per_user does not exist as a pam_tally2 option.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Display Lockout. piney Linux - Hardware 1 04-29-2010 05:19 PM
NT domain lockout r3g Linux - Networking 0 03-22-2006 03:10 AM
Login Lockout John Manion Linux - Newbie 1 11-16-2003 12:53 AM
Lockout Problem! sanju2k Linux - General 1 12-01-2002 08:33 AM
sandbox lockout... jwhiz Linux - Newbie 2 10-02-2002 04:04 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration