[tac_plus] Question about failed logins

Andy Ruhl acruhl at gmail.com
Fri Jan 15 18:17:04 UTC 2016


I'm looking for advice or direction on failed logins.

I have tac_plus F4.0.4.28 running on Linux.

It's using pam for authentication.

I'm required to lock out users after 5 failed login attempts, but the
problem is that when I log into an average Cisco switch, it seems to
create a failed login attempt before I'm even prompted for a password:

[root at machine ~]# pam_tally2
Login           Failures Latest failure     From
acruhl              1    01/15/16 11:05:12  unknown

So if I log into a few switches I get locked out even if I never put
in an incorrect password.

Is there some option to prevent this failed login? I've done some
searching but I really hope I didn't miss something obvious.

Thanks,

Andy


More information about the tac_plus mailing list