UCF STIG Viewer Logo

The delay between login prompts following a failed login attempt must be at least 4 seconds.


Overview

Finding ID Version Rule ID IA Controls Severity
V-220022 GEN000480 SV-220022r854393_rule Medium
Description
Enforcing a delay between successive failed login attempts increases protection against automated password guessing attacks.
STIG Date
Solaris 10 SPARC Security Technical Implementation Guide 2022-09-07

Details

Check Text ( C-21731r482729_chk )
Check the SLEEPTIME parameter in the /etc/default/login file.

# grep SLEEPTIME /etc/default/login

If SLEEPTIME is not listed, commented out, or less than 4, this is a finding.
Fix Text (F-21730r482730_fix)
Edit the /etc/default/login file and set SLEEPTIME to 4.