security-misc/usr/share/pam-configs/tally2-security-misc
Patrick Schleizer 6757104aa4
use pam_tally2 only for login
to skip counting failed login attempts over ssh and mail login
2021-01-24 05:04:48 -05:00

12 lines
449 B
Plaintext

Name: lock accounts after 50 failed authentication attempts (by package security-misc)
Default: yes
Priority: 290
Auth-Type: Primary
Auth:
optional pam_exec.so debug stdout seteuid /usr/lib/security-misc/pam_tally2-info
[success=1 default=ignore] pam_exec.so seteuid quiet /usr/lib/security-misc/pam_only_if_login
requisite pam_tally2.so even_deny_root deny=50 onerr=fail audit debug
Account-Type: Primary
Account:
requisite pam_tally2.so debug