Ø  3. Upgrade to 7.6 which I think has this feature

It actually is in AR System 7.0.01 or later:

Max Number of Password Attempts
Enter the maximum number of consecutive bad password
attempts a user is allowed. If you enter 3, the user has 3 chances
to log in. If all 3 attempts have bad passwords, the user account
will be marked as INVALID.
The allowed values for this field are 0 and all positive integers.
A value of 0 turns feature off. This setting can also be set with
the Max-Password-Attempts option in the ar.conf
(ar.cfg) file.

-David J. Easter
Sr. Product Manager, Enterprise Service Management
BMC Software, Inc.

The opinions, statements, and/or suggested courses of action expressed in this 
E-mail do not necessarily reflect those of BMC Software, Inc.  My voluntary 
participation in this forum is not intended to convey a role as a spokesperson, 
liaison or public relations representative for BMC Software, Inc.

From: Action Request System discussion list(ARSList) 
[mailto:[email protected]] On Behalf Of Frank Caruso
Sent: Wednesday, November 10, 2010 9:24 AM
To: [email protected]
Subject: Disable Account after Bad Password Attempt

** ARS 6.3 p24
Oracle
Solaris

Have a requirement to disable a users account after so many bad password 
attempts in a certain time period. We are using Remedy authentication (not tied 
to AD). Some thoughts on how to do this:

1. Parse the User log file in real time.
2. Build a custom arealdap.so to intercept the login response.
3. Upgrade to 7.6 which I think has this feature

Thoughts?

Frank Caruso

_attend WWRUG11 www.wwrug.com ARSlist: "Where the Answers Are"_

_______________________________________________________________________________
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
attend wwrug11 www.wwrug.com ARSList: "Where the Answers Are"

Reply via email to