From owner-freebsd-security@FreeBSD.ORG Thu Oct 30 10:35:54 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 7E62416A4CE for ; Thu, 30 Oct 2003 10:35:54 -0800 (PST) Received: from mail.numachi.com (meisai.numachi.com [198.175.254.6]) by mx1.FreeBSD.org (Postfix) with SMTP id 5797F43F3F for ; Thu, 30 Oct 2003 10:35:49 -0800 (PST) (envelope-from reichert@numachi.com) Received: (qmail 76813 invoked from network); 30 Oct 2003 18:35:46 -0000 Received: from natto.numachi.com (198.175.254.216) by meisai.numachi.com with SMTP; 30 Oct 2003 18:35:46 -0000 Received: (qmail 98196 invoked by uid 1001); 30 Oct 2003 18:35:46 -0000 Date: Thu, 30 Oct 2003 13:35:46 -0500 From: Brian Reichert To: Michael Carlson Message-ID: <20031030183546.GE91120@numachi.com> References: <5.1.1.6.0.20031030084448.03831060@popcorn.llnl.gov> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <5.1.1.6.0.20031030084448.03831060@popcorn.llnl.gov> User-Agent: Mutt/1.5.4i cc: freebsd-security@freebsd.org Subject: Re: your mail X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 30 Oct 2003 18:35:54 -0000 On Thu, Oct 30, 2003 at 08:45:03AM -0800, Michael Carlson wrote: > > I have asked this before in -questions but due to a odd security > requirement, I need the option to auto lock a normal user's account > (root and those in the wheel group must be excluded) after let say, 3, > login failures. I know this can cause a DoS issue but I HAVE to have > the option of doing it in FreeBSD. I don't much experience with pam(8), but there is some mention of 'sessions' in the manpage: session - this group of tasks cover things that should be done prior to a service being given and after it is with- drawn. Such tasks include the maintenance of audit trails and the mounting of the user's home directory. The session management group is important as it provides both an open- ing and closing hook for modules to affect the services available to a user. Perhaps that's a place to introduce a hook for what you need... > Any info is appreciated > Thanks. > Mike C > carlson39@llnl.gov -- Brian 'you Bastard' Reichert 37 Crystal Ave. #303 Daytime number: (603) 434-6842 Derry NH 03038-1713 USA BSD admin/developer at large