diff --git a/files/common/var/lib/delphix-platform/ansible/10-delphix-platform/roles/delphix-platform/tasks/main.yml b/files/common/var/lib/delphix-platform/ansible/10-delphix-platform/roles/delphix-platform/tasks/main.yml index 0f3b59ba..318e9ebe 100644 --- a/files/common/var/lib/delphix-platform/ansible/10-delphix-platform/roles/delphix-platform/tasks/main.yml +++ b/files/common/var/lib/delphix-platform/ansible/10-delphix-platform/roles/delphix-platform/tasks/main.yml @@ -336,6 +336,28 @@ regexp: '^#?[\s]*(auth[\s]+required[\s]+pam_wheel\.so.*)$' replace: '\1' +# +# +# Lock out the user after an unsuccessful consecutive login attempts. +# +- lineinfile: + path: /etc/pam.d/common-auth + line: "{{ item }}" + insertafter: BOF + with_items: + - 'auth required pam_tally2.so audit silent deny=5 unlock_time=900' + +# +# +# Configuration to remember user password history. +# +- lineinfile: + path: /etc/pam.d/common-account + line: "{{ item }}" + insertafter: EOF + with_items: + - 'account required pam_tally2.so' + # # Enable SNMP client tools to load MIBs by default. #