Go to main content

Oracle® SuperCluster M8 and SuperCluster M7 Security Guide

Exit Print View

Updated: June 2020
 
 

Configure a Failed Authentication Lock Delay

By default, the storage servers implement a policy where a system account is locked for 10 minutes after any single failed authentication attempt.

To change this threshold, perform this procedure.

  1. Log into the storage server as celladmin.

    See Log into the Storage Server OS.

  2. View the current setting.
    # /opt/oracle.cellos/host_access_control pam-auth --status | grep lock_time=
    
  3. Change the threshold.

    To comply with U.S. Department of Defense security requirements, set the value to 4 seconds. If necessary, replace that value with one that is compliant with your local site policies.

    # /opt/oracle.cellos/host_access_control pam-auth --lock 4
    
  4. To verify the setting, repeat Step 2.