STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 3 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to VMware vSphere 7.0 vCenter Appliance Photon OS Security Technical Implementation Guide

V-256479

CAT II (Medium)

The Photon operating system must automatically lock an account when three unsuccessful logon attempts occur.

Rule ID

SV-256479r958388_rule

STIG

VMware vSphere 7.0 vCenter Appliance Photon OS Security Technical Implementation Guide

Version

V1R4

CCIs

CCI-000044, CCI-002238

Discussion

By limiting the number of failed logon attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-force attacks, is reduced. Limits are imposed by locking the account. Satisfies: SRG-OS-000021-GPOS-00005, SRG-OS-000329-GPOS-00128

Check Content

At the command line, run the following commands:

# grep pam_tally2 /etc/pam.d/system-auth

Expected result:

auth       required pam_tally2.so deny=3 onerr=fail audit even_deny_root unlock_time=900 root_unlock_time=300

# grep pam_tally2 /etc/pam.d/system-account

Expected result:

account    required pam_tally2.so onerr=fail audit

If the output does not list the "pam_tally2" options as configured in the expected results, this is a finding.

Fix Text

Navigate to and open:

/etc/pam.d/system-auth

Remove any existing "pam_tally2.so" line and add the following line after the "pam_unix.so" statement:

auth       required pam_tally2.so deny=3 onerr=fail audit even_deny_root unlock_time=900 root_unlock_time=300

Navigate to and open:

/etc/pam.d/system-account

Remove any existing "pam_tally2.so" line and add the following line after the "pam_unix.so" statement:

account    required pam_tally2.so onerr=fail audit

Note: On vCenter appliances, the equivalent file must be edited under "/etc/applmgmt/appliance", if one exists, for the changes to persist after a reboot.