CompTIA Linux+ (XK0-006)SecurityMedium
A system administrator needs to ensure that all users on a Linux server are subject to a maximum of 3 failed login attempts before their account is locked out for 5 minutes. Which PAM configuration file should be modified to implement this policy for local user authentication?
- A/etc/pam.d/common-auth
- B/etc/pam.d/system-auth
- C/etc/pam.d/sshd
- D/etc/pam.d/login
Show answer & explanationAnswer & explanation
Correct answer: A. /etc/pam.d/common-auth
To apply a failed login attempt policy to all authentication services that use common PAM configurations, /etc/pam.d/common-auth is the most appropriate file. Modifying this file centrally impacts services linked to it, such as login and sshd, ensuring consistent policy enforcement.
Why the other options are wrong
- B. /etc/pam.d/system-auth is another common include, but common-auth is often used for authentication-specific settings like 'auth' module types, which include faillock.
- C. /etc/pam.d/sshd specifically targets SSH authentication and would not apply to other local login methods.
- D. /etc/pam.d/login specifically targets console login and would not apply to other services like SSH.
PAM common-auth
The /etc/pam.d/common-auth file is a common PAM configuration file used to define authentication policies that apply to multiple services on a Linux system.
- Often included by other service-specific PAM files (e.g., login, sshd).
- Used for defining authentication-related modules like pam_unix.so or pam_faillock.so.
- Modifying it provides a centralized way to enforce system-wide authentication policies.
Memory trick: PAM's Common Auth is like a central library for all login rules.