View the security misconfiguration catalog
  • Misconfiguration Name
  • Account lockout policy is not configured
  • Description
  • A brute force attack occurs when an attacker attempts to guess a password with multiple login attempts. Fixing this misconfiguration will configure Pluggable Authentication Module (PAM) to lock accounts after 5 consecutive, failed login attempts and keep the account locked out for 150 minutes after the account lockout is triggered.
  • Severity
  • important
  • Category
  • Linux - Password Policies
  • Resolution
  • Fix not available
  • Potential issues that may arise after applying the resolution
  • Altering the existing security setting may create the following impact in your network operations.
  • Does remediation require reboot?
  • No