Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-1075: How to monitor local account login failures using pam_tally

Centrify DirectAudit ,   Centrify DirectControl ,   Centrify Identity Service, Mac Edition ,  

12 April,16 at 11:45 AM

Applies to:  All versions of Centrify DirectControl
 


Question:


How to monitor local account login failures using pam_tally on a server with Centrify agent installed?



Answer:


The latest releases of Linux PAM includes a module called pam_tally which rejects a user if the user failed to login too many times. Although this functionality is not coordinated with Windows domain policy settings, the use of pam_tally may add value for local account logins.

If the requirement is to monitor local account login failures then place pam_tally after the Centrify lines:
 
auth       sufficient     pam_centrifydc.so
auth       requisite      pam_centrifydc.so deny
account    sufficient     pam_centrifydc.so
account    requisite      pam_centrifydc.so deny
session    required       pam_centrifydc.so homedir
password   sufficient     pam_centrifydc.so try_first_pass
password   requisite      pam_centrifydc.so deny
auth       required /lib/security/$ISA/pam_tally.so per_user deny=3 onerr-fail
account    required /lib/security/$ISA/pam_tally.so


Placing pam_tally auth and account after the Centrify lines means that an AD user login failure will not be recorded.  Only a local user who falls through all Centrify checking will come to this pam_tally logic.

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.