OK. I was mostly looking for a scorable control(s).

On 8/14/15 2:34 PM, Paul Whitney wrote:
I use pam_tally2 for that.


Paul Whitney
email: [email protected]
cell: 410.493.9448

Sent from my iPhone

On Aug 14, 2015, at 13:47, Ron Colvin <[email protected]> wrote:

A patch for the SSH bug that bypassed the MaxAuthTries limit was just patched. 
Has MaxAuthTries been considered as a control in the security guide?

http://www.openssh.com/txt/release-7.0
https://threatpost.com/openssh-7-0-fixes-four-flaws/114265

--


********************************************************
Ron Colvin CISSP, CAP, CEH
Certified Security Analyst
NASA - Goddard Space Flight Center
<[email protected]>
Direct phone 301-286-2451
NASA Jabber ([email protected]) AIM rcolvin13
NASA LCS ([email protected])
********************************************************



--


********************************************************
Ron Colvin CISSP, CAP, CEH
Certified Security Analyst
NASA - Goddard Space Flight Center
<[email protected]>
Direct phone 301-286-2451
NASA Jabber ([email protected]) AIM rcolvin13
NASA LCS ([email protected])
********************************************************


Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

-- 
SCAP Security Guide mailing list
[email protected]
https://lists.fedorahosted.org/mailman/listinfo/scap-security-guide
https://github.com/OpenSCAP/scap-security-guide/

Reply via email to