Ø 3. Upgrade to 7.6 which I think has this feature It actually is in AR System 7.0.01 or later:
Max Number of Password Attempts Enter the maximum number of consecutive bad password attempts a user is allowed. If you enter 3, the user has 3 chances to log in. If all 3 attempts have bad passwords, the user account will be marked as INVALID. The allowed values for this field are 0 and all positive integers. A value of 0 turns feature off. This setting can also be set with the Max-Password-Attempts option in the ar.conf (ar.cfg) file. -David J. Easter Sr. Product Manager, Enterprise Service Management BMC Software, Inc. The opinions, statements, and/or suggested courses of action expressed in this E-mail do not necessarily reflect those of BMC Software, Inc. My voluntary participation in this forum is not intended to convey a role as a spokesperson, liaison or public relations representative for BMC Software, Inc. From: Action Request System discussion list(ARSList) [mailto:[email protected]] On Behalf Of Frank Caruso Sent: Wednesday, November 10, 2010 9:24 AM To: [email protected] Subject: Disable Account after Bad Password Attempt ** ARS 6.3 p24 Oracle Solaris Have a requirement to disable a users account after so many bad password attempts in a certain time period. We are using Remedy authentication (not tied to AD). Some thoughts on how to do this: 1. Parse the User log file in real time. 2. Build a custom arealdap.so to intercept the login response. 3. Upgrade to 7.6 which I think has this feature Thoughts? Frank Caruso _attend WWRUG11 www.wwrug.com ARSlist: "Where the Answers Are"_ _______________________________________________________________________________ UNSUBSCRIBE or access ARSlist Archives at www.arslist.org attend wwrug11 www.wwrug.com ARSList: "Where the Answers Are"

