三级等保之Linux密码安全

96 阅读1分钟

设置linux的密码强度

sudo vim /etc/pam.d/system-auth

auth        required      pam_faillock.so preauth audit deny=3 even_deny_root unlock_time=300

password    requisite     pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type= minlen=12 lcredit=-1 ucredit=-1 dcredit=-1 ocredit=-1 enforce_for_root

配置sshd登录失,锁住

sudo vim /etc/pam.d/sshd

auth  required  pam_faillock.so preauth silent audit even_deny_root deny=3 unlock_time=300

设置存活时间

sudo vim /etc/profile

export TMOUT=600

sudo vim /etc/login.defs

2、 配置: PASS_MAX_DAYS 90 PASS_MIN_DAYS 2 PASS_MIN_LEN 8

SecretKey012345678901234567890123456789012345678901234567890123456789