DLPX-86530 CIS: delphix user lockout after failed login attempts #474
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Background
CIS: delphix user lockout after failed login attempts
JIRA: https://delphix.atlassian.net/browse/DLPX-86530
Solution
Updating the pam modules
common-auth and common-account
to enforcedelphix
user lockout policies usingpam_tally2.so
Testing Done
http://selfservice.jenkins.delphix.com/job/appliance-build-orchestrator-pre-push/8569/console
http://selfservice.jenkins.delphix.com/job/appliance-build-orchestrator-pre-push/8523/console -
In-progress
http://selfservice.jenkins.delphix.com/job/appliance-build-orchestrator-pre-push/8456/ -
In-progress
http://selfservice.jenkins.delphix.com/job/appliance-build-orchestrator-pre-push/8394/ -
In-progress
http://selfservice.jenkins.delphix.com/job/appliance-build-orchestrator-pre-push/8391/ -
In-progress
http://selfservice.jenkins.delphix.com/job/appliance-build-orchestrator-pre-push/8389/console -
Successful
With 4 unsuccessful login attempts and 5th successful login attempt with
delphix
user -With 5 unsuccessful login attempts and entering correct password at 6th attempt with
delphix
user -delphix
user lockout already happened and after unlock time completion connection to engine will be successful with correct password.Re-login to engine with delphix user after unlock period is over -