- http://www.fprog.org/~mura-masa/diary/?date=20111130
- man pam_tally2
/etc/pam.d/password-auth
authã®åé é¨åã«è¿½è¨ã(pam_env.soã®æ¬¡ï¼)
ä¸ã®ä¾ã¯åè¨å¤±æ3åããã¨ããã¯ãããã(ããã¯ãããã¾ã§ã®éä¸ã«ä¸åº¦ã§ãèªè¨¼æåããã失æåæ°ã¯ã¯ãªã¢ããã)
auth required pam_env.so auth required pam_tally2.so deny=3
å½ç¶ã ãã©sshã®èªè¨¼ã§å©ç¨ããå ´åã¯sshd_configã«UsePAM yes ã¨è¨è¿°ãã¦ãããã¨ã
pam_tally2 option
- deny=n
失æåæ°ããã®æ°å¤ã«éããã¨ããã¯ãã
- unlock_time=n
æå¾ã«å¤±æãã¦ãããã®è¨å®ç§æ°çµéããã¨ã¢ã³ããã¯ãããè¨å®ããªãå ´åãpam_tally2 ã³ãã³ãã§æåã§(ãããã¯cronãªã©ã§å®æçã«)ã¢ã³ããã¯ããã¾ã§ãã¦ã¼ã¶ã¯ããã¯ãããã¾ã¾
- even_deny_root
rootãããã¯å¯¾è±¡ã«å«ãããã©ãããdefaultã¯å«ã¾ãªã
- root_unlock_time=n
rootã®unlock_timeãåå¥ã«è¨å®ããå ´åã¯ãããæå®
log
/var/log/tallylog
# binaryãªã®ã§ç´æ¥è¦ãã®ã§ã¯ãªãã¦ãpam_tally2 ã³ãã³ããå
é¨çã«åç
§ãã¦ãããã°
確èª
# pam_tally2 [-u username]
失æåæ°ããªã»ãã
# pam_tally2 -u user --reset